Starting And Stopping The Local Ca Server 39+\27 - Cisco PIX 500 Series Configuration Manual

Security appliance command line
Hide thumbs Also See for PIX 500 Series:
Table of Contents

Advertisement

Chapter 39
Configuring Certificates
The Local CA WebVPN login screen is provided in the following figure:
Starting and Stopping the Local CA Server
When you complete Local CA Server configuration, to activate it, use the no shutdown command. To
disable enrollment and/or to modify the configuration, use the shutdown command
Enabling the Local CA Server
Initially, you need to specify a passphrase to create and protect the archive of the CA certificate and keypair
that are generated. The passphrase unlocks the PKCS12 archive in case the CA certificate or keypair are lost.
Once you enable the Local CA server, with the no shutdown command, it generates the Local CA server
certificate, keypair and necessary database files, and also archives the Local CA server certificate and keypair
to storage in a PKCS12 file. After the initial startup, you can issue no shutdown and shutdown commands
that enable and disable the Local CA without being prompted for the passphrase.
Once you enable the Local CA Server, be sure to save the configuration to ensure that the Local CA
Note
certificate and keypair are not lost after a reboot.
At initial startup, you are prompted for the passphrase in the CLI as illustrated in the example that follows.
To enable the Local CA server on a security appliance, perform the following steps:
Create a password (7-character min.) in order to encode and archive a PKCS12 file containing the Local
Step 1
CA certificate and keypair that is to be generated.
Step 2
Enter the following command to enable the Local CA server on the security appliance. The command
requires an 8-65 alphanumeric character password:
hostname(config)# crypto ca server
hostname(config-ca-server)# no shutdown
hostname(config-ca-server)#
hostname(config-ca-server)# no shutdown
% Some server settings cannot be changed after CA certificate generation.
% Please enter a passphrase to protect the private key
% or type Return to exit
Password: caserver
OL-12172-03
Cisco Security Appliance Command Line Configuration Guide
The Local CA
39-27

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5500 series

Table of Contents