1-44
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring Digital Certificates
Feature History for Certificate Management
Certificate management
8.0(2)
We introduced the following commands:
cdp-url
,
crypto ca server
,
crypto ca server crl issue
,
crypto ca server revoke
cert-serial-no,
crypto ca server
unrevoke
cert-serial-no,
crypto ca server user-db add
user
[
dn
dn
e-mail-address
],
crypto ca server
user-db allow
{
username
|
all-unenrolled
|
all-certholders
} [
display-otp
] [
email-otp
] [
replace-otp
],
crypto ca server user-db email-otp
{
username
|
all-unenrolled
|
all-certholders
},
crypto ca server
user-db remove
username,
crypto ca server user-db
show-otp
{
username
|
all-certholders
|
all-unenrolled
},
crypto ca server user-db write
,
[no] database path
mount-name directory-path,
debug crypto ca server
[
level
],
lifetime {ca-certificate
|
certificate | crl
}
time,
no
shutdown,
otp expiration
timeout,
renewal-reminder
time,
show crypto ca server
,
show crypto ca server
cert-db [user
username
| allowed | enrolled | expired |
on-hold] [serial
certificate-serial-number
],
show crypto
ca server certificate
,
show crypto ca server crl
,
show
crypto ca server user-db
[
expired
|
allowed
|
on-hold
|
enrolled
],
show crypto key
name of key,
show
running-config
,
shutdown
.
SCEP proxy
8.4(1)
We introduced this feature, which provides secure
deployment of device certificates from third-party CAs.
We introduced the following commands:
crypto ikev2 enable outside client-services port
portnumber
,
scep-enrollment enable
,
scep-forwarding-url value
URL
,
secondary-pre-fill-username clientless hide
use-common-password
password
,
secondary-pre-fill-username ssl-client hide
use-common-password
password
,
secondary-username-from-certificate
{
use-entire-name
|
use-script
| {
primary_attr
[
secondary-attr
]}}
[
no-certificate-fallback cisco-secure-desktop
machine-unique-id
].
Table 1-1
Feature History for Certificate Management (continued)
Feature Name
Platform
Releases
Feature Information
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......