Local Ca Certificate Rollover 39+\35; Archiving The Local Ca Server Certificate And Keypair 39+\35; Deleting The Local Ca Server 39+\35 - Cisco PIX 500 Series Configuration Manual

Security appliance command line
Hide thumbs Also See for PIX 500 Series:
Table of Contents

Advertisement

Chapter 39
Configuring Certificates
Local CA Certificate Rollover
Thirty days prior to the expiration of the Local CA certificate, a rollover replacement certificate is
generated, and a syslog message informs the administrator that it is time for Local CA rollover. The new
Local CA certificate must be imported onto all necessary devices prior to the expiration of the current
certificate. If the administrator does not respond by installing the rollover certificate as the new Local
CA certificate, validations can begin to fail.
The Local CA certificate rolls over automatically upon expiration using the same keypair. The rollover
certificate is available for export in base64 format and can be displayed using the crypto ca server
certificate command, which displays both the current and the rollover certificates. This command shows
information about the rollover certificate when available, including the thumbprint of the rollover
certificate for verification of the new certificate during import on other devices.
Archiving the Local CA Server Certificate and Keypair
For backup purposes, you can use FTP or TFTP to copy the Local CA Server certificate and keypair and
all files from the security appliance. An example follows:
hostname#
hostname# copy LOCAL-CA-SERVER_0001.pl2 tftp://90.1.1.22/user6/
Back up all Local CA files as often as possible.
Note
Deleting the Local CA Server
Deleting the Local CA Server removes the configuration from the security appliance. Once deleted, the
Note
configuration is unrecoverable.
To delete the existing Local CA server, whether it is enabled or disabled, you must issue a no crypto ca
server command or a clear config crypto ca server command in Global Configuration mode, and then
delete the associated database and configuration files (all files with the wildcard name,
LOCAL-CA-SERVER.*).
OL-12172-03
Cisco Security Appliance Command Line Configuration Guide
The Local CA
39-35

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5500 series

Table of Contents