Cisco Systems OL-16647-01 User Manual

Browse online or download User Manual for Hardware firewalls Cisco Systems OL-16647-01. Cisco Systems OL-16647-01 User's Manual

  • Download
  • Add to my manuals
  • Print
  • Page
    / 20
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 0
CHAPTER
33-1
Cisco Security Appliance Command Line Configuration Guide
OL-16647-01
33
Configuring Certificates
Digital certificates provide digital identification for authentication. A digital certificate contains
information that identifies a device or user, such as the name, serial number, company, department, or IP
address. CAs issue digital certificates in the context of a PKI, which uses public-key/private-key
encryption to ensure security. CAs are trusted authorities that “sign” certificates to verify their
authenticity, thus guaranteeing the identity of the device or user.
For authentication using digital certificates, there must be at least one identity certificate and its issuing
CA certificate on a security appliance, which allows for multiple identities, roots and certificate
hierarchies. There a number of different types of digital certificates listed below:
A CA certificate is one used to sign other certificates. A CA certificate that is self-signed is called
a root certificate; one issued by another CA certificate is called a subordinate certificate. See CA
Certificate Authentication.
CAs also issue identity certificates, which are the certificates for specific systems or hosts. See
Identity Certificates Authentication.
Code-signer certificates are special certificates used to create digital signatures to sign code, with
the signed code itself revealing the certificate origin. See Code-Signer Certificates
The Local Certificate Authority (CA) integrates an independent certificate authority functionality
on the security appliance, deploys certificates, and provides secure revocation checking of issued
certificates. The Local CA provides a secure configurable inhouse authority for certificate
authentication with user enrollment by browser web page login. See Local Certificate Authority,
Manage User Certificates, and Manage User Database.
CA Certificate Authentication
The CA Certificates panel allows you to authenticate self-signed or subordinate CA certificates and to
install them on the security appliance. You can create a new certificate configuration or you can edit an
existing one.
If the certificate you select is configured for manual enrollment, you should obtain the CA certificate
manually and import it here. If the certificate you select is configured for automatic enrollment, the
security appliance uses the SCEP protocol to contact the CA, and then automatically obtains and installs
the certificate.
CA Certificates Fields
Certificates —Displays a list of the certificates available identified by issued to and by, the date the
certificate expires, and the certificate’s usage or purpose. You can click a certificate in the list and
edit its configuration, or you can add a new certificate to the displayed list.
Page view 0
1 2 3 4 5 6 ... 19 20

Summary of Contents

Page 1 - Configuring Certificates

CHAPTER 33-1Cisco Security Appliance Command Line Configuration GuideOL-16647-0133Configuring CertificatesDigital certificates provide digital identif

Page 2 - Add/Install a CA Certificate

33-10Cisco Security Appliance Command Line Configuration GuideOL-16647-01Chapter 33 Configuring Certificates Identity Certificates Authenticati

Page 3

33-11Cisco Security Appliance Command Line Configuration GuideOL-16647-01Chapter 33 Configuring Certificates Code-Signer CertificatesTo Add the

Page 4

33-12Cisco Security Appliance Command Line Configuration GuideOL-16647-01Chapter 33 Configuring Certificates Local Certificate Authority• Delet

Page 5

33-13Cisco Security Appliance Command Line Configuration GuideOL-16647-01Chapter 33 Configuring Certificates Local Certificate AuthorityNote Th

Page 6

33-14Cisco Security Appliance Command Line Configuration GuideOL-16647-01Chapter 33 Configuring Certificates Local Certificate AuthorityConfigu

Page 7

33-15Cisco Security Appliance Command Line Configuration GuideOL-16647-01Chapter 33 Configuring Certificates Local Certificate AuthorityCA Serv

Page 8

33-16Cisco Security Appliance Command Line Configuration GuideOL-16647-01Chapter 33 Configuring Certificates Local Certificate AuthorityPublish

Page 9

33-17Cisco Security Appliance Command Line Configuration GuideOL-16647-01Chapter 33 Configuring Certificates Local Certificate AuthorityEnrollm

Page 10 - OL-16647-01

33-18Cisco Security Appliance Command Line Configuration GuideOL-16647-01Chapter 33 Configuring Certificates Manage User CertificatesManage Use

Page 11

33-19Cisco Security Appliance Command Line Configuration GuideOL-16647-01Chapter 33 Configuring Certificates Manage User DatabaseEmail OTPThe E

Page 12 - Local Certificate Authority

33-2Cisco Security Appliance Command Line Configuration GuideOL-16647-01Chapter 33 Configuring Certificates CA Certificate Authentication• Add

Page 13 - Default Local CA Server

33-20Cisco Security Appliance Command Line Configuration GuideOL-16647-01Chapter 33 Configuring Certificates Manage User Database

Page 14 - Issuer Name

33-3Cisco Security Appliance Command Line Configuration GuideOL-16647-01Chapter 33 Configuring Certificates CA Certificate AuthenticationMore O

Page 15

33-4Cisco Security Appliance Command Line Configuration GuideOL-16647-01Chapter 33 Configuring Certificates CA Certificate AuthenticationConfig

Page 16 - Database Storage Location

33-5Cisco Security Appliance Command Line Configuration GuideOL-16647-01Chapter 33 Configuring Certificates CA Certificate AuthenticationCRL Re

Page 17 - Deleting the Local CA Server

33-6Cisco Security Appliance Command Line Configuration GuideOL-16647-01Chapter 33 Configuring Certificates Identity Certificates Authenticatio

Page 18 - Manage User Database

33-7Cisco Security Appliance Command Line Configuration GuideOL-16647-01Chapter 33 Configuring Certificates Identity Certificates Authenticatio

Page 19 - View/Re-generate OTP

33-8Cisco Security Appliance Command Line Configuration GuideOL-16647-01Chapter 33 Configuring Certificates Identity Certificates Authenticatio

Page 20 - Manage User Database

33-9Cisco Security Appliance Command Line Configuration GuideOL-16647-01Chapter 33 Configuring Certificates Identity Certificates Authenticatio

Comments to this Manuals

No comments