Manual Cisco Systems OL-16647-01

20 pages 0.21 mb
Download

Go to site of 20

Summary
  • Cisco Systems OL-16647-01 - page 1

    CH A P T E R 33-1 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 33 Configuring Certificates Digital certif icates provide digit al identif ication for authenti cation. A digital cert ificate contain s informa tion that id entifies a device or user , such as the name, serial number , compan y , department, or IP address. CA ...

  • Cisco Systems OL-16647-01 - page 2

    33-2 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates CA Certificate Authentication • Add Button —Add a ne w certif icate conf igurat ion to the list. See Add/Install a CA Certif icate . • Edit Button —Modify an existing cert ificat e conf iguration. See Edit CA Certif icat e Conf igu ...

  • Cisco Systems OL-16647-01 - page 3

    33-3 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates CA Certificate Authentication More Options... —F or additional op tions for ne w certif icates, click the Mor e Options... button to display conf iguration opti ons for ne w and existi ng certifi cates. See Conf iguratio n Options for ...

  • Cisco Systems OL-16647-01 - page 4

    33-4 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates CA Certificate Authentication Configuration Options for CA Certi ficates Additional conf igurat ion options are a v ailable, whet her you are addin g a ne w CA certif icate with the Add button o r modifying an e xisting CA certif icate wit ...

  • Cisco Systems OL-16647-01 - page 5

    33-5 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates CA Certificate Authentication CRL Retrieval Method Configuration The CRL Retri ev a l Method pan el lets yo u select the method to be used for CRL retrie val. • Click the Enable Lightweight Directory A ccess Protocol (LD AP) but ton to ...

  • Cisco Systems OL-16647-01 - page 6

    33-6 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Identity Certific ates Authentication T o avo id havi ng to retrie v e the same CRL from a CA repeatedly , The security appliance can store retrie ved CRLs local ly , which is called CRL caching. The CRL cache ca pacity varies b y platform ...

  • Cisco Systems OL-16647-01 - page 7

    33-7 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Identity Certificates Authentication Add/Install an Identity Certificate The Identity Certif icate panel lets you imp ort an exi sting identity certif icate from a file or add a ne w certificate conf iguration fr om an existing fi le. Cl ...

  • Cisco Systems OL-16647-01 - page 8

    33-8 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Identity Certific ates Authentication – The check box Include serial number of the de vice allo ws you to add the security appliance serial number t o the certif icate p arameters. – The Advanced > Enrollment M ode allo ws you to se ...

  • Cisco Systems OL-16647-01 - page 9

    33-9 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Identity Certificates Authentication • Issued to — Displays the X.50 0 fields o f the subject DN or certif icate owner and their v alues. This applies only to a v ailable stat us. • Issued by —Displays the X.500 fields of the ent ...

  • Cisco Systems OL-16647-01 - page 10

    33-10 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Identity Certific ates Authentication Generate Certificate Signin g Request This pane lets you generate a certif icate signin g request to send to En trust. Be aw are that at the ti me of this release, Entrust support s key mo dulus of si ...

  • Cisco Systems OL-16647-01 - page 11

    33-11 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Code-Signer Certificates To Add the Identity Certificate: Step 1 In the Identity Certificates panel , click the Add but t on . Step 2 In the Add Identity Cert if icate panel, select Add a new identity certif icate . Step 3 Optionally , ...

  • Cisco Systems OL-16647-01 - page 12

    33-12 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority • Delete an existing Identity Certificate. See Delete a Code-Signer Certificate . Export an e xisting Identity Certif icate. See Import or Export a Code-Si gner Certif icate . Show Code-Signer Certificate Det ...

  • Cisco Systems OL-16647-01 - page 13

    33-13 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority Note The local CA provides a certificat e authority on the adaptiv e secur ity appliance for use with SSL VPN connections, both brow ser - and client-based. User enrollment is by bro wser webpage login. The L ...

  • Cisco Systems OL-16647-01 - page 14

    33-14 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority Configuring the Local CA Sever The CA Serv er windo w lets you cust omize, modify , and control Local CA server operation. This section describes the parameters that can be specified. Additional paramete rs ar ...

  • Cisco Systems OL-16647-01 - page 15

    33-15 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority CA Server Key Size The CA Ke y Size parameter is the size of the used for the serv er certif icate generated fo r the Local CA server . Ke y size can be 512, 768, 1024, or 2048 bits per ke y . The default siz ...

  • Cisco Systems OL-16647-01 - page 16

    33-16 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority Publish CRL Interface and Port: T o make the CRL av ailable for HTTP do wnload on a gi ven interface or port. Sel ect an interface from the pull-do wn list. The opt ional port option can be an y port number in ...

  • Cisco Systems OL-16647-01 - page 17

    33-17 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority Enrollment Period The Enrollment Period field specif i es the number of hours an en roll ed user can retriev e a PKCS12 enrollment f ile in order to enroll and retri ev e a user certif icate. The enrollm ent ...

  • Cisco Systems OL-16647-01 - page 18

    33-18 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Manage User Certificates Manage User Certificates The Local CA server maintains certificate rene wals, re-issues user certificates, maintains t he Certificate Re vocation List (CRL), and rev o kes or restores pri vil eges as needed. With ...

  • Cisco Systems OL-16647-01 - page 19

    33-19 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Manage User Data base Email OTP The Email O TP butt on automatically send s an e-mail noti ce of enrollment permission with a unique one-time passwo rd (O TP) and th e Local CA enrollment w ebpage URL to the ne wly added u ser . Replace ...

  • Cisco Systems OL-16647-01 - page 20

    33-20 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Manage User Database ...

Manufacturer Cisco Systems Category Switch

Documents that we receive from a manufacturer of a Cisco Systems OL-16647-01 can be divided into several groups. They are, among others:
- Cisco Systems technical drawings
- OL-16647-01 manuals
- Cisco Systems product data sheets
- information booklets
- or energy labels Cisco Systems OL-16647-01
All of them are important, but the most important information from the point of view of use of the device are in the user manual Cisco Systems OL-16647-01.

A group of documents referred to as user manuals is also divided into more specific types, such as: Installation manuals Cisco Systems OL-16647-01, service manual, brief instructions and user manuals Cisco Systems OL-16647-01. Depending on your needs, you should look for the document you need. In our website you can view the most popular manual of the product Cisco Systems OL-16647-01.

A complete manual for the device Cisco Systems OL-16647-01, how should it look like?
A manual, also referred to as a user manual, or simply "instructions" is a technical document designed to assist in the use Cisco Systems OL-16647-01 by users. Manuals are usually written by a technical writer, but in a language understandable to all users of Cisco Systems OL-16647-01.

A complete Cisco Systems manual, should contain several basic components. Some of them are less important, such as: cover / title page or copyright page. However, the remaining part should provide us with information that is important from the point of view of the user.

1. Preface and tips on how to use the manual Cisco Systems OL-16647-01 - At the beginning of each manual we should find clues about how to use the guidelines. It should include information about the location of the Contents of the Cisco Systems OL-16647-01, FAQ or common problems, i.e. places that are most often searched by users in each manual
2. Contents - index of all tips concerning the Cisco Systems OL-16647-01, that we can find in the current document
3. Tips how to use the basic functions of the device Cisco Systems OL-16647-01 - which should help us in our first steps of using Cisco Systems OL-16647-01
4. Troubleshooting - systematic sequence of activities that will help us diagnose and subsequently solve the most important problems with Cisco Systems OL-16647-01
5. FAQ - Frequently Asked Questions
6. Contact detailsInformation about where to look for contact to the manufacturer/service of Cisco Systems OL-16647-01 in a specific country, if it was not possible to solve the problem on our own.

Do you have a question concerning Cisco Systems OL-16647-01?

Use the form below

If you did not solve your problem by using a manual Cisco Systems OL-16647-01, ask a question using the form below. If a user had a similar problem with Cisco Systems OL-16647-01 it is likely that he will want to share the way to solve it.

Copy the text from the picture

Comments (0)