39-31
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 39 Configuring Certificates
The Local CA
Revocation Checking
The Local CA maintains a current Certification Revocation List (CRL) with serial numbers of all
revoked user certificates. This list is available to external devices and can be retrieved directly from the
Local CA if it is configured as such with the
cdp-url
and the
publish-crl
CLI commands. When you
revoke (or unrevoke) any current certificate, by certificate serial number, the CRL reflect these changes.
Displaying Local CA Server Information
There are various ways to display and print the Local CA server configuration and user information as
described in the following subsections. The following table summarizes the Local CA Server CLI
commands that display configuration and database information.
Display Local CA Configuration
To display the characteristics of the configured Local CA, use the
show crypto ca server
command in
Privileged EXEC mode. The following is a sample
show crypto ca server
display.
Display Certificate Database
To display a list with all of the certificates issued by the Local CA, use the
show crypto ca server
cert-db command
in Privileged EXEC mode. The following is a sample
show crypto ca server cert-db
command
display showing just two of the user certificates in the database.
Command
Display
show crypto ca server
Local CA configuration and status
show crypto ca server cert-db
User certificate(s)
show crypto ca server certificate
Local CA certificate
show crypto ca server crl
Certificate Revocation List
show crypto ca server user-db
Users and their status
show crypto ca server user-db allowed
Users eligible to enroll.
show crypto ca server user-db enrolled
Enrolled users with valid certificate
show crypto ca server user-db expired
Users with an expired certificate.
show crypto ca server user-db on-hold
Users without certificate not permitted to enroll
Certificate Server LOCAL-CA-SERVER:
Status: enabled
State: enabled
Server's configuration is locked (enter "shutdown" to unlock it)
Issuer name: CN=wz5520-1-16
CA certificate fingerprint/thumbprint: (MD5)
76dd1439 ac94fdbc 74a0a89f cb815acc
CA certificate fingerprint/thumbprint: (SHA1)
58754ffd 9f19f9fd b13b4b02 15b3e4be b70b5a83
Last certificate issued serial number: 0x6
CA certificate expiration timer: 14:25:11 UTC Jan 16 2008
CRL NextUpdate timer: 16:09:55 UTC Jan 24 2007
Current primary storage dir: flash:
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......