EasyManuals Logo

Cisco 5510 - ASA SSL / IPsec VPN Edition Configuration Guide

Cisco 5510 - ASA SSL / IPsec VPN Edition
1822 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #729 background imageLoading...
Page #729 background image
CHAPTER
35-1
Cisco ASA 5500 Series Configuration Guide using ASDM
OL-20339-01
35
Configuring Digital Certificates
This chapter describes how to configure digital certificates and includes the following sections:
Information About Digital Certificates, page 35-1
Licensing Requirements for Digital Certificates, page 35-8
Configuring CA Certificate Authentication, page 35-9
Configuring Identity Certificates Authentication, page 35-14
Configuring Code Signer Certificates, page 35-20
Authenticating Using the Local CA, page 35-22
Managing the User Database, page 35-25
Managing User Certificates, page 35-28
Monitoring CRLs, page 35-28
Feature History for Certificate Management, page 35-29
Information About Digital Certificates
Digital certificates provide digital identification for authentication. A digital certificate includes
information that identifies a device or user, such as the name, serial number, company, department, or IP
address. CAs are trusted authorities that “sign” certificates to verify their authenticity, thereby
guaranteeing the identity of the device or user. CAs issue digital certificates in the context of a PKI,
which uses public-key or private-key encryption to ensure security.
For authentication using digital certificates, at least one identity certificate and its issuing CA certificate
must exist on an adaptive security appliance. This configuration allows multiple identities, roots, and
certificate hierarchies. Descriptions of several different types of available digital certificates follow:
A CA certificate is used to sign other certificates. It is self-signed and called a root certificate. A
certificate that is issued by another CA certificate is called a subordinate certificate. For more
information, see the “Configuring CA Certificate Authentication” section on page 35-9.
CAs also issue identity certificates, which are certificates for specific systems or hosts. For more
information, see the “Configuring Identity Certificates Authentication” section on page 35-14.
Code-signer certificates are special certificates that are used to create digital signatures to sign code,
with the signed code itself revealing the certificate origin. For more information, see the
“Configuring Code Signer Certificates” section on page 35-20.

Table of Contents

Other manuals for Cisco 5510 - ASA SSL / IPsec VPN Edition

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 5510 - ASA SSL / IPsec VPN Edition and is the answer not in the manual?

Cisco 5510 - ASA SSL / IPsec VPN Edition Specifications

General IconGeneral
BrandCisco
Model5510 - ASA SSL / IPsec VPN Edition
CategoryFirewall
LanguageEnglish

Related product manuals