Chapter 33 Configuring Certificates
Local Certificate Authority
CA Server Key Size
The CA Key Size parameter is the size of the used for the server certificate generated for the Local CA server. Key size can be 512, 768, 1024, or 2048 bits per key. The default size is 1024 bits per key.
Client Key Size
The Key Size field specifies the size of the key pair to be generated for each user certificate issued by the Local CA server. Key size can be 512, 768, 1024, or 2048 bits per key. The default size is 1024 bits per key.
CA Certificate Lifetime
The CA Certificate Lifetime field specifies the length of time in days that the CA server certificate is valid. The default for the CA Certificate is 3650 days (10 years).
The Local CA Server automatically generates a replacement CA certificate 30 days prior to the CA certificate expiration, allowing the replacement certificate to be exported and imported onto any other devices for Local CA certificate validation of user certificates issued by the Local CA certificate after expiration. The
ment certificate is available for export.
Note When notified of this automatic rollover, the administrator must take action to ensure the new Local CA certificate is imported to all necessary devices prior to expiration.
Client Certificate Lifetime
The Client Certificate Lifetime field specifies the length of time in days that a user certificate issued by the CA server is valid. The default for the CA Certificate is 365 days (one year).
SMTP Server & Email Settings
To set up
astandard subject line for Local CA
•Server IP Address - The Server IP Address field requires the Local CA
•From Address - The From Address field requires an
•Subject - The Subject field is a line of text specifying the subject line in all
More Local CA Configuration Options
CRL Distribution Point URL
The Certificate Revocation List (CRL) Distribution Point (CDP) is the location of the CRL on the security appliance. The default CRL DP location is http://hostname.domain/+CSCOCA+/asa_ca.crl.
|
| Cisco Security Appliance Command Line Configuration Guide |
|
| |
|
|
| |||
|
|
|
|
| |
|
|
|
|