39-17
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 39 Configuring Certificates
The Local CA
As shown in
Figure 39-1
, the Local CA server, configurable from both CLI and ASDM, resides on the
security appliance and handles enrollment requests from web page users and CRL inquiries coming from
other certificate validating devices and security appliances. Local CA database and configuration files
are maintained either on the security appliance flash memory (default storage) or on a separate storage
device.
Figure 39-1
The Local Certificate Authority (CA)
Note
Only one Local CA server can be resident on a security appliance at a time, and the Local CA cannot be
configured as a subordinate to an external CA.
Configuring the Local CA Server
This section describes how to configure the Local CA server on the security appliance and includes the
following topics:
•
The Default Local CA Server, page 39-17
•
Customizing the Local CA Server, page 39-19
•
Certificate Characteristics, page 39-20
The Default Local CA Server
The default Local CA server requires only a few configuration commands to set up with the following
characteristics. Once you use the
crypto ca server
command to access config-ca-server mode, all you
must specify are CLI commands described in the following steps:
Step 1
Specify the SMTP (Simple Mail Transfer Protocol) from-address with the
smtp from-address
command. This command provides a valid e-mail address the Local CA uses as a from: address when
sending e-mails that deliver one-time passwords for an enrollment invitation to users.
User Enrollment Webpage
for PKCS12 Users Certificate
Enrollment and Retrieval
HTTP CRL retrieval
ASDM and CLI
configuration and
management
Local Database in flash memory
or Mounted external file system
(CIFS or FTP)
Security Device
with Local CA
Configured
191783
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......