33-22
Cisco ASDM User Guide
OL-16647-01
Chapter 33 Configuring Certificates
Local Certificate Authority
Configuring the Local CA Sever
The CA Server window lets you customize, modify, and control Local CA server operation. This section
describes the parameters that can be specified. Additional parameters are available when you click More
Options. See More Local CA Configuration Options. For permanent removal of a configured Local CA,
see Deleting the Local CA Server. To customize the Local CA server, first review the initial settings
shown in the preceding table.
Note Issuer-name and keysize server values cannot be changed once you enable the Local CA. Be sure to
review all optional parameters carefully before you enable the configured Local CA.
Enable/Disable Buttons
The Enable/Disable buttons activate or deactivate the Local CA server. Once you enable the Local CA
server with the Enable button, the security appliance generates the Local CA server certificate, key pair
and necessary database files.
The self-signed certificate key usage extension has key encryption, key signature, CRL signing, and
certificate signing ability. The Enable button also archives the Local CA server certificate and key pair
to storage in a PKCS12 file.
Length of time a one-time password is valid 72 hrs. (three days)
Caution: Delete Certificate Authority Server button permanently removes the server configuration.
Configurable Parameters Defaults