41-27
Cisco ASA 5500 Series Configuration Guide using the CLI
Chapter41 Configuring Digital Certificates
Configuring Digital Certificates
Configuring Local CA Certificate Characteristics
You can configure the following characteristics of local CA certificates:
The name of the certificate issuer as it appears on all user certificates.
The lifetime of the local CA certificates (server and user) and the CRL.
The length of the public and private keypairs associated with local CA and user certificates.
This section includes the following topics:
Configuring the Issuer Name, page41-28
Configuring the CA Certificate Lifetime, page41-28
Configuring the User Certificate Lifetime, page41-29
Configuring the CRL Lifetime, page41-30
Configuring the Server Keysize, page41-30
Setting Up External Local CA File Storage, page41-31
Downloading CRLs, page41-33
Storing CRLs, page 41-34
Setting Up Enrollment Parameters, page41-35
Adding and Enrolling Users, page41-36
Renewing Users, page 41-38
Restoring Users, page41-39
Removing Users, page41-39
Revoking Certificates, page41-40
Maintaining the Local CA Certificate Database, page 41-40
Rolling Over Local CA Certificates, page41-40
Archiving the Local CA Server Certificate and Keypair, page41-41
no crypto ca server
Example:
hostname (config)# no crypto ca server
Removes an existing local CA server (either enabled or
disabled).
Note Deleting the local CA server removes the
configuration from the ASA. After the configuration
has been deleted, it is unrecoverable.
Make sure that you also delete the associated local CA server
database and configuration files (that is, all files with the
wildcard name, LOCAL-CA-SERVER.*).
clear configure crypto ca server
Example:
hostname (config)# clear config crypto ca server
Command Purpose