39-35
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 39 Configuring Certificates
The Local CA
Local CA Certificate Rollover
Thirty days prior to the expiration of the Local CA certificate, a rollover replacement certificate is
generated, and a syslog message informs the administrator that it is time for Local CA rollover. The new
Local CA certificate must be imported onto all necessary devices prior to the expiration of the current
certificate. If the administrator does not respond by installing the rollover certificate as the new Local
CA certificate, validations can begin to fail.
The Local CA certificate rolls over automatically upon expiration using the same keypair. The rollover
certificate is available for export in base64 format and can be displayed using the
crypto ca server
certificate
command, which displays both the current and the rollover certificates. This command shows
information about the rollover certificate when available, including the thumbprint of the rollover
certificate for verification of the new certificate during import on other devices.
Archiving the Local CA Server Certificate and Keypair
For backup purposes, you can use FTP or TFTP to copy the Local CA Server certificate and keypair and
all files from the security appliance. An example follows:
hostname#
hostname# copy LOCAL-CA-SERVER_0001.pl2 tftp://90.1.1.22/user6/
Note
Back up all Local CA files as often as possible.
Deleting the Local CA Server
Note
Deleting the Local CA Server removes the configuration from the security appliance. Once deleted, the
configuration is unrecoverable.
To delete the existing Local CA server, whether it is enabled or disabled, you must issue a
no crypto ca
server
command or a
clear config crypto ca server
command in Global Configuration mode, and then
delete the associated database and configuration files (all files with the wildcard name,
LOCAL-CA-SERVER.*).
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......