44-29
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter44 Configuring Digital Certificates
Managing User Certificates

Deleting a Local CA User

To remove the user from the database and any certificates issued to that user from the local CA database,
select the user, and then click Delete.
Note A deleted user cannot be restored. To recreate the deleted user record, click Add to reenter all of the user
information.

Allowing User Enrollment

To enroll the selected user, click Allow Enrollment.
The status of the user changes to “enrolled” in the Manage User Database pane.
Note If the user is already enrolled, an error message appears.

Viewing or Regenerating an OTP

To view or regenerate the OTP of the selected user, perform the following steps:
Step1 Click View/Regenerate OTP to display the View & Regenerate OTP dialog box.
The current OTP appears.
Step2 After you are done, click OK to close the View & Regenerate OTP dialog box.
Step3 To regenerate the OTP, click Regenerate OTP.
The newly generated OTP appears.
Step4 Click OK to close the View & Regenerate OTP dialog box.
What to Do Next
See the “Managing User Certificates” section on page 44-29.
Managing User Certificates
To change the certificate status, perform the following steps:
Step1 In the Manage User Certificates pane, select specific certificates by username or by certificate serial
number.
Step2 Choose one of the following options:
If the user certificate lifetime period runs out, to remove user access, click Revoke. The local CA
also marks the certificate as revoked in the certificate database, automatically updates the
information, and reissues the CRL.