CHAPTER
 
1-1
Cisco ASA Series CLI Configuration Guide
 
1
Configuring Digital Certificates
This chapter describes how to configure digital certificates and includes the following sections:
• Information About Digital Certificates, page 1-1
• Licensing Requirements for Digital Certificates, page 1-7
• Prerequisites for Local Certificates, page 1-7
• Guidelines and Limitations, page 1-8
• Configuring Digital Certificates, page 1-9
• Monitoring Digital Certificates, page 1-41
• Feature History for Certificate Management, page 1-43
Information About Digital Certificates
CAs are responsible for managing certificate requests and issuing digital certificates. A digital certificate 
includes information that identifies a user or device, such as a name, serial number, company, 
department, or IP address. A digital certificate also includes a copy of the public key for the user or 
device. A CA can be a trusted third party, such as VeriSign, or a private (in-house) CA that you establish 
within your organization.
Tip For an example of a scenario that includes certificate configuration and load balancing, see the following 
URL: https://supportforums.cisco.com/docs/DOC-5964.
This section includes the following topics:
• Public Key Cryptography, page 1-2
• Certificate Scalability, page 1-2
• Key Pairs, page 1-2
• Trustpoints, page 1-3
• Revocation Checking, page 1-4
• The Local CA, page 1-6