39-18
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 39 Configuring Certificates
The Local CA
Step 2
For an optional subject-name DN appended to each username on issued certificates, specify the
subject-name DN with the
subject-name-default
command. The subject-name DN and the username
combine to form the DN in all user certificates issued by the Local CA server. If you do not specify a
subject-name DN, you must specify the exact subject name DN to be included in a user certificate each
time you add a user to the user database.
The following example shows the few CLI commands required to configure and enable the Local CA
server when you are using the predefined default values for all required parameters.
hostname(config)#
crypto ca server
hostname (config-ca-server) #
smtp from-address
hostname (config-ca-server)#
subject-name-default
cn=engineer, o=asc Systems, c=US
hostname(config-ca-server)# no shutdown
All other required parameter values are the system defaults.
Table 39-1
lists the configurable
characteristics of the Local CA server, their pre-defined default values, and the CLI commands that
configure them.
Note
Issuer-name
and
keysize server
values cannot be changed after you enable the Local CA initially. Be
sure to review all optional parameters carefully before you enable the configured Local CA.
Table 39-1
Local CA Local CA Server Default Characteristics
Local CA Server Characteristic
Default Value
CLI Configuration
Command(s)
Storage Location for database and
configuration
On-board flash memory in the
directory LOCAL-CA-SERVER.
mount
(global
config mode)
database path
Certificate Issuer Name
cn=
FQDN
issuer-name
Enabled/disabled.
no-shutdown
enables
the Local CA;
shutdown
disables it.
No Local CA Server configured.
shutdown
vs.
no
shutdown
(enables)
Access to config-ca-server mode and Local
CA server configuration commands
No server enabled
crypto ca server
Issued certificate keypair size
1024 bits per key
keysize
Local CA Certificate key-pair size
1024 bits per key
keysize server
Length of time a user certificate, server
certificate, or CRL is valid
User Certificate=1 yr.; Server
Certificate=3 yrs.; CRL=6 hours
lifetime
Length of time a one-time password is valid Expires in 72 hrs. (three days)
otp-expiration
Certificate Revocation List (CRL)
Distribution Point (CDP), the location of the
CRL on the Local CA security appliance or
on an external server
For a local CRL, the same as
security appliance,
http://
hostname.domain
/+CSCOC
A+/asa_ca.crl
cdp-url
* E-mail address issuing Local CA e-mail
notices
Required.
You must supply an
e-mail address as the default,
admin@
FQDN,
might not be an
actual address.
smtp from-address
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......