Cisco ASA 5505 Configuration Manual page 740

Asa 5500 series
Hide thumbs Also See for ASA 5505:
Table of Contents

Advertisement

Configuring CA Certificate Authentication
Check the Use CRL Distribution Point from the certificate check box to direct revocation checking
Step 2
to the CRL distribution point from the certificate being checked.
Step 3
Check the Use Static URLs configured below check box to list specific URLs to be used for CRL
retrieval. The URLs you select are implemented in the order in which you add them. If an error occurs
with the specified URL, the next URL in order is taken.
In the Static Configuration area, click Add.
Step 4
The Add Static URL dialog box appears.
In the URL field, enter the static URL to use for distributing the CRLs, and then click OK.
Step 5
The URL that you entered appears in the Static URLs list.
Step 6
To change the static URL, select it, and then click Edit.
Step 7
To remove an existing static URL, select it, and then click Delete.
To change the order in which the static URLs appear, click Move Up or Move Down.
Step 8
Click OK to close this tab. Alternatively, to continue, see the
Step 9
section on page
Configuring CRL Retrieval Methods
To configure CRL retrieval methods, perform the following steps:
In the Configuration Options for CA Certificates pane, click the CRL Retrieval Methods tab.
Step 1
Choose one of the following three retrieval methods:
Step 2
Click OK to close this tab. Alternatively, to continue, see the
Step 3
page
Cisco ASA 5500 Series Configuration Guide using ASDM
35-12
35-12.
To enable LDAP for CRL retrieval, check the Enable Lightweight Directory Access Protocol
(LDAP) check box. With LDAP, CRL retrieval starts an LDAP session by connecting to a named
LDAP server, accessed by a password. The connection is on TCP port 389 by default. Enter the
following required parameters:
Name
Password
Confirm Password
Default Server (server name)
Default Port (389)
To enable HTTP for CRL retrieval, check the Enable HTTP check box.
To enable SCEP for CRL retrieval, check the Enable Simple Certificate Enrollment Protocol
(SCEP) check box.
35-13.
Chapter 35
Configuring Digital Certificates
"Configuring CRL Retrieval Methods"
"Configuring OCSP Rules" section on
OL-20339-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5510Asa 5540Asa 5520Asa 5550Asa 5580

Table of Contents