33-10
Cisco ASDM User Guide
OL-16647-01
Chapter 33 Configuring Certificates
CA Certificate Authentication
The security appliance supports two methods of checking revocation status: CRL and OCSP.
Fields
CRL Options
Cache Refresh Time—Specify the number of minutes between cache refreshes. The default
number of minutes is 60. The range is 1-1440.
To avoid having to retrieve the same CRL from a CA repeatedly, The security appliance can
store retrieved CRLs locally, which is called CRL caching. The CRL cache capacity varies by
platform and is cumulative across all contexts. If an attempt to cache a newly retrieved CRL
would exceed its storage limits, the security appliance removes the least recently used CRL until
more space becomes available.
Enforce next CRL update—Require valid CRLs to have a Next Update value that has not
expired. Clearing the box allows valid CRLs with no Next Update value or a Next Update value
that has expired.
OCSP Options
Server URL:—Enter the URL for the OCSP server. The security appliance uses OCSP servers
in the following order:
1. OCSP URL in a match certificate override rule
2. OCSP URL configured in this OCSP Options attribute
3. AIA field of remote user certificate