Setting up enrollment parameters – Cisco ASA 5505 User Manual

Page 853

Advertising
background image

41-35

Cisco ASA 5500 Series Configuration Guide using the CLI

Chapter 41 Configuring Digital Certificates

Configuring Digital Certificates

Setting Up Enrollment Parameters

To set up enrollment parameters, perform the following steps:

Command

Purpose

Step 1

crypto ca server

Example:

hostname (config)# crypto ca server

Enters local ca server configuration mode. Allows
you to configure and manage a local CA.

Step 2

otp expiration

timeout

Example:

hostname(config-ca-server)# otp expiration 24

Specifies the number of hours that an issued OTP for
the local CA enrollment page is valid. The default
expiration time is 72 hours.

Note

The user OTP to enroll for a certificate on the
enrollment website is also used as the
password to unlock the PKCS12 file that
includes the issued certificate and keypair for
the specified user.

Step 3

enrollment-retrieval

timeout

Example:

hostname(config-ca-server)# enrollment-retrieval 120

Specifies the number of hours an already-enrolled
user can retrieve a PKCS12 enrollment file.This time
period begins when the user is successfully enrolled.
The default retrieval period is 24 hours. Valid values
for the retrieval period range from 1 to 720 hours. The
enrollment retrieval period is independent of the OTP
expiration period.

After the enrollment retrieval time expires, the user
certificate and keypair are no longer available. The
only way a user may receive a certificate is for the
administrator to reinitialize certificate enrollment
and allow a user to log in again.

Advertising