39-12
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 39 Configuring Certificates
Certificate Configuration
% The fully-qualified domain name in the certificate will be:
securityappliance.example.com
% Include the device serial number in the subject name? [yes/no]:
n
Display Certificate Request to terminal? [yes/no]:
y
Certificate Request follows:
MIIBoDCCAQkCAQAwIzEhMB8GCSqGSIb3DQEJAhYSRmVyYWxQaXguY2lzY28uY29t
[ certificate request data omitted ]
jF4waw68eOxQxVRbIOYmvt8g6hnBTrd0GdqjjVLt
---End - This line not part of the certificate request---
Redisplay enrollment request? [yes/no]:
n
hostname (config)#
Note
If you use separate RSA keys for signing and encryption, the
crypto ca enroll
command
displays two certificate requests, one for each key. To complete enrollment, acquire a certificate
for all certificate requests generated by the
crypto ca enroll
command.
Step 4
For each request generated by the
crypto ca enroll
command, obtain a certificate from the CA
represented by the applicable trustpoint. Be sure the certificate is in base-64 format.
Step 5
For each certificate you receive from the CA, use the
crypto ca import certificate
command. The
security appliance prompts you to paste the certificate to the terminal in base-64 format.
Note
If you use separate RSA key pairs for signing and encryption, perform this step for each
certificate separately. The security appliance determines automatically whether the certificate is
for the signing or encryption key pair. The order in which you import the two certificates is
irrelevant.
The following example manually imports a certificate for the trustpoint Main:
hostname (config)#
crypto ca import Main certificate
% The fully-qualified domain name in the certificate will be:
securityappliance.example.com
Enter the base 64 encoded certificate.
End with a blank line or the word “quit” on a line by itself
[ certificate data omitted ]
quit
INFO: Certificate successfully imported
hostname (config)#
Step 6
Verify that the enrollment process was successful using the
show crypto ca certificate
command. For
example, to show the certificate received from trustpoint Main:
hostname/contexta(config)#
show crypto ca certificate Main
The output of this command shows the details of the certificate issued for the security appliance and the
CA certificate for the trustpoint.
Step 7
Save the configuration using the
write memory
command:
hostname/contexta(config)#
write memory
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......