EasyManuals Logo

Cisco 5510 - ASA SSL / IPsec VPN Edition Configuration Guide

Cisco 5510 - ASA SSL / IPsec VPN Edition
1822 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #741 background imageLoading...
Page #741 background image
35-13
Cisco ASA 5500 Series Configuration Guide using ASDM
OL-20339-01
Chapter 35 Configuring Digital Certificates
Configuring CA Certificate Authentication
Configuring OCSP Rules
The adaptive security appliance examines OCSP rules in priority order, and applies the first one that
matches. X.509 digital certificates are an alternative to using CRLs.
Note Make sure that you have configured a certificate map before you try to add OCSP rules. If a certificate
map has not been configured, an error message appears. To configure a certificate map, choose
Configuration > Network (Client) Access, Advanced > IPSec > Certificate to Connection Profile
Maps > Rules > Add.
To configure OCSP rules for obtaining revocation status of an X.509 digital certificate, perform the
following steps:
Step 1 In the Configuration Options for CA Certificates pane, click the OCSP Rules tab.
Step 2 Choose the certificate map to match to this OCSP rule. Certificate maps match user permissions to
specific fields in a certificate. The name of the CA that the adaptive security appliance uses to validate
responder certificates appears in the Certificate field. The priority number for the rule appears in the
Index field. The URL of the OCSP server for this certificate appears in the URL field.
Step 3 To add a new OCSP rule, click Add.
The Add OCSP Rule dialog box appears.
Step 4 Choose the certificate map to use from the drop-down list.
Step 5 Choose the certificate to use from the drop-down list.
Step 6 Enter the priority number for the rule.
Step 7 Enter the URL of the OCSP server for this certificate.
Step 8 When you are done, click OK to close this dialog box.
The newly added OCSP rule appears in the list.
Step 9 To edit an existing OCSP rule, select it, and then click Edit.
Step 10 To delete an OCSP rule, select it, and then click Delete.
Step 11 Click OK to close this tab. Alternatively, to continue, see the “Configuring Advanced CRL and OCSP
Settings” section on page 35-13.
Configuring Advanced CRL and OCSP Settings
When a certificate is issued, it is valid for a fixed period of time. Sometimes a CA revokes a certificate
before this time period expires; for example, because of security concerns or a change of name or
association. CAs periodically issue a signed list of revoked certificates. Enabling revocation checking
forces the adaptive security appliance to check that the CA has not revoked the certificate being verified.
The adaptive security appliance supports two methods of checking revocation status: CRL and OCSP.
To configure additional CRL and OCSP settings, perform the following steps:
Step 1 In the Configuration Options for CA Certificates pane, click the Advanced tab.

Table of Contents

Other manuals for Cisco 5510 - ASA SSL / IPsec VPN Edition

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 5510 - ASA SSL / IPsec VPN Edition and is the answer not in the manual?

Cisco 5510 - ASA SSL / IPsec VPN Edition Specifications

General IconGeneral
BrandCisco
Model5510 - ASA SSL / IPsec VPN Edition
CategoryFirewall
LanguageEnglish

Related product manuals