39-34
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 39 Configuring Certificates
The Local CA
dn: <None>
allowed: <not allowed>
notified: 0
hostname (config)#
Local CA Server Maintenance and Backup Procedures
The stored Local CA Server configuration, users, issued certificates, CRL, etc. reside in the database in
flash memory, or in file-system storage, depending on how you configure storage. The following
subsections describe database maintenance procedures.
Maintaining the Local CA User Database
Each time the security appliance configuration is saved, all user information in the Local CA Server
database is saved automatically (with the
write memory
command) to the file specified by the
database
path
command when you set up file storage external to the security appliance. For example, if you set
up file storage using the following command:
hostname(config)# crypto ca server
hostname(config-ca-server)# database path mydata:newuser
hostname(config-ca-server)#
User database information is saved from the security appliance to
mydata /newuser
every time you save
the security appliance configuration.
Note
For flash memory database storage, the user information is saved automatically to the default location
for the start-up configuration.
Maintaining the Local CA Certificate Database
The certificate database file, LOCAL-CA-SERVER.cdb, is to be saved anytime there is a change in the
database.
•
LOCAL-CA-SERVER.p12 is the archive of the Local CA certificate and keypair generated when the
Local CA server is initially enabled
with the
no shutdown
command
.
•
LOCAL-CA-SERVER.crl file is the actual CRL.
•
LOCAL-CA-SERVER.ser file is used to keep track of the issued certificate serial numbers
The Local CA files can be seen on the flash memory or in external storage as follows:
hostname(config-ca-server)# dir LOCAL* //
Directory of disk0:/LOCAL*
75 -rwx 32 13:07:49 Jan 20 2007 LOCAL-CA-SERVER.ser
77 -rwx 229 13:07:49 Jan 20 2007 LOCAL-CA-SERVER.cdb
69 -rwx 0 01:09:28 Jan 20 2007 LOCAL-CA-SERVER.udb
81 -rwx 232 19:09:10 Jan 20 2007 LOCAL-CA-SERVER.crl
72 -rwx 1603 01:09:28 Jan 20 2007 LOCAL-CA-SERVER.p12
127119360 bytes total (79693824 bytes free)
hostname (config-ca-server)#
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......