1-35
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring Digital Certificates
Configuring Digital Certificates
Setting Up Enrollment Parameters
To set up enrollment parameters, perform the following commands:
Command
Purpose
Step 1
crypto ca server
Example:
hostname (config)# crypto ca server
Enters local ca server configuration mode. Allows
you to configure and manage a local CA.
Step 2
otp expiration
timeout
Example:
hostname(config-ca-server)# otp expiration 24
Specifies the number of hours that an issued OTP for
the local CA enrollment page is valid. The default
expiration time is 72 hours.
Note
The user OTP to enroll for a certificate on the
enrollment website is also used as the
password to unlock the PKCS12 file that
includes the issued certificate and keypair for
the specified user.
Step 3
enrollment-retrieval
timeout
Example:
hostname(config-ca-server)# enrollment-retrieval 120
Specifies the number of hours an already-enrolled
user can retrieve a PKCS12 enrollment file.This time
period begins when the user is successfully enrolled.
The default retrieval period is 24 hours. Valid values
for the retrieval period range from 1 to 720 hours. The
enrollment retrieval period is independent of the OTP
expiration period.
After the enrollment retrieval time expires, the user
certificate and keypair are no longer available. The
only way a user may receive a certificate is for the
administrator to reinitialize certificate enrollment
and allow a user to log in again.
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......