39-27
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 39 Configuring Certificates
The Local CA
The Local CA WebVPN login screen is provided in the following figure:
Starting and Stopping the Local CA Server
When you complete Local CA Server configuration, to activate it, use the
no shutdown
command. To
disable enrollment and/or to modify the configuration, use the
shutdown
command
Enabling the Local CA Server
Initially, you need to specify a passphrase to create and protect the archive of the CA certificate and keypair
that are generated. The passphrase unlocks the PKCS12 archive in case the CA certificate or keypair are lost.
Once you enable the Local CA server, with the
no shutdown
command, it generates the Local CA server
certificate, keypair and necessary database files, and also archives the Local CA server certificate and keypair
to storage in a PKCS12 file. After the initial startup, you can issue
no shutdown
and
shutdown
commands
that enable and disable the Local CA without being prompted for the passphrase.
Note
Once you enable the Local CA Server, be sure to save the configuration to ensure that the Local CA
certificate and keypair are not lost after a reboot.
At initial startup, you are prompted for the passphrase in the CLI as illustrated in the example that follows.
To enable the Local CA server on a
security appliance
, perform the following steps:
Step 1
Create a password (7-character min.) in order to encode and archive a PKCS12 file containing the Local
CA certificate and keypair that is to be generated.
Step 2
Enter the following command to enable the Local CA server on the security appliance. The command
requires an 8-65 alphanumeric character password:
hostname(config)#
crypto ca server
hostname(config-ca-server)#
no shutdown
hostname(config-ca-server)#
hostname(config-ca-server)# no shutdown
% Some server settings cannot be changed after CA certificate generation.
% Please enter a passphrase to protect the private key
% or type Return to exit
Password: caserver
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......