33-25
Cisco ASDM User Guide
OL-16647-01
Chapter 33 Configuring Certificates
Local Certificate Authority
That Local CA database resides can be configured to be on an off-box file system that is mounted and
accessible to the security appliance. To specify an external file or share, enter the pathname to the
external file or click Browse and search for the file.
Note Flash memory can store a database with 3500 users or less, but a database of more than 3500
users requires off-box storage.
Default Subject Name
The Default Subject Name (DN) field allows you to specify a default subject name to append to a username
on issued certificates. The permitted DN attribute keywords are listed in the following list:
Enrollment Period
The Enrollment Period field specifies the number of hours an enrolled user can retrieve a PKCS12
enrollment file in order to enroll and retrieve a user certificate. The enrollment period is independent of
the OTP expiration period. The default Enrollment Period is 24 hours.
Note Certificate enrollment for the Local CA is supported only for Clientless SSL VPN connections
and is not supported for other SSL VPN clients such as CVC or for IPSec VPN connections. For
clientless SSL VPN connections, communications between the client and the head-end is
through a web browser utilizing standard HTML.
One-Time-Password Expiration
The One-Time-Password (OTP) expiration field specifies the length of time that a one-time password
e-mailed to an enrolling user is valid. The default value is 72 hours.
Certificate Expiration Reminder
The Certificate Expiration Reminder field specifies the number of days before expiration reminders are
sent to e-mailed to users. The default is 14 days.
Apply Button
The Apply button lets you save the new or modified CA certificate configuration.
Default Subject-name-default DN Keywords
CN= Common Name
SN = Surname
O = Organization Name
L = Locality
C = Country
OU = Organization Unit
EA = E-mail Address
ST = State/Province
T = Title