39-28
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 39 Configuring Certificates
The Local CA
Re-enter password: caserver
Keypair generation process begin. Please wait...
hostname(config-ca-server)#
Re-enabling the same Local CA Server with the
no shutdown
command and disabling it with the
shutdown
command do not require the passphrase.
Debugging the Local CA Server
To debug the newly configured Local CA Server, use the
debug crypto ca server
command in global
configuration mode. This command displays debug messages when you configure and enable the Local
CA server. By default, the
debug crypto ca server
command performs level 1 debug functions; levels
1-255 are available.
Note
Debug commands might slow down traffic on busy networks. Levels 5 and higher are reserved for raw
data dumps and should be avoided during normal debugging because of excessive debug output.
Disabling the Local CA Server
When you disable the Local CA server with the
shutdown
command, the configuration and all associated
files remain in storage. Webpage enrollment is disabled, but you can change or reconfigure the Local CA
Server during shutdown and then restart it with the
no shutdown
command.
To disable the Local CA server on a
security appliance
, perform the following:
asa1(config-ca-server)#
asa1(config-ca-server)# shutdown
INFO: Local CA Server has been shutdown.
asa1(config-ca-server)#
Managing the Local CA User Database
The Local CA server keeps track of user certificates, so the administrator can revoke or restore privileges
as needed. This section describes how to add, allow for enrollment, remove, and manage users in the
Local CA database with CLI commands. These operations are all initiated with the
crypto ca server
user-db
(function)
command in Privileged Exec mode. The functions are summarized in
Table 39-2
Crypto CA Server User Commands
and described in the following subsections.
Note that users must be added to the database with the
crypto ca server user-db add
command, but it
is the
crypto ca server user-db allow
command that grants each user enrollment privileges.
Table 39-2
Crypto CA Server User Commands
Command
Description
crypto ca server user-db add
Adds a user to the Local CA server user database.
crypto ca server user-db allow
Permits a specific user or subset of users in the Local CA
server database to enroll and generates OTPs for users.
crypto ca server user-db remove
Removes a user from the Local CA server user database by
user name.
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......