Cisco Systems OL-16647-01 manual

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20

Go to page of

A good user manual

The rules should oblige the seller to give the purchaser an operating instrucion of Cisco Systems OL-16647-01, along with an item. The lack of an instruction or false information given to customer shall constitute grounds to apply for a complaint because of nonconformity of goods with the contract. In accordance with the law, a customer can receive an instruction in non-paper form; lately graphic and electronic forms of the manuals, as well as instructional videos have been majorly used. A necessary precondition for this is the unmistakable, legible character of an instruction.

What is an instruction?

The term originates from the Latin word „instructio”, which means organizing. Therefore, in an instruction of Cisco Systems OL-16647-01 one could find a process description. An instruction's purpose is to teach, to ease the start-up and an item's use or performance of certain activities. An instruction is a compilation of information about an item/a service, it is a clue.

Unfortunately, only a few customers devote their time to read an instruction of Cisco Systems OL-16647-01. A good user manual introduces us to a number of additional functionalities of the purchased item, and also helps us to avoid the formation of most of the defects.

What should a perfect user manual contain?

First and foremost, an user manual of Cisco Systems OL-16647-01 should contain:
- informations concerning technical data of Cisco Systems OL-16647-01
- name of the manufacturer and a year of construction of the Cisco Systems OL-16647-01 item
- rules of operation, control and maintenance of the Cisco Systems OL-16647-01 item
- safety signs and mark certificates which confirm compatibility with appropriate standards

Why don't we read the manuals?

Usually it results from the lack of time and certainty about functionalities of purchased items. Unfortunately, networking and start-up of Cisco Systems OL-16647-01 alone are not enough. An instruction contains a number of clues concerning respective functionalities, safety rules, maintenance methods (what means should be used), eventual defects of Cisco Systems OL-16647-01, and methods of problem resolution. Eventually, when one still can't find the answer to his problems, he will be directed to the Cisco Systems service. Lately animated manuals and instructional videos are quite popular among customers. These kinds of user manuals are effective; they assure that a customer will familiarize himself with the whole material, and won't skip complicated, technical information of Cisco Systems OL-16647-01.

Why one should read the manuals?

It is mostly in the manuals where we will find the details concerning construction and possibility of the Cisco Systems OL-16647-01 item, and its use of respective accessory, as well as information concerning all the functions and facilities.

After a successful purchase of an item one should find a moment and get to know with every part of an instruction. Currently the manuals are carefully prearranged and translated, so they could be fully understood by its users. The manuals will serve as an informational aid.

Table of contents for the manual

  • Page 1

    CH A P T E R 33-1 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 33 Configuring Certificates Digital certif icates provide digit al identif ication for authenti cation. A digital cert ificate contain s informa tion that id entifies a device or user , such as the name, serial number , compan y , department, or IP address. CA[...]

  • Page 2

    33-2 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates CA Certificate Authentication • Add Button —Add a ne w certif icate conf igurat ion to the list. See Add/Install a CA Certif icate . • Edit Button —Modify an existing cert ificat e conf iguration. See Edit CA Certif icat e Conf igu[...]

  • Page 3

    33-3 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates CA Certificate Authentication More Options... —F or additional op tions for ne w certif icates, click the Mor e Options... button to display conf iguration opti ons for ne w and existi ng certifi cates. See Conf iguratio n Options for [...]

  • Page 4

    33-4 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates CA Certificate Authentication Configuration Options for CA Certi ficates Additional conf igurat ion options are a v ailable, whet her you are addin g a ne w CA certif icate with the Add button o r modifying an e xisting CA certif icate wit[...]

  • Page 5

    33-5 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates CA Certificate Authentication CRL Retrieval Method Configuration The CRL Retri ev a l Method pan el lets yo u select the method to be used for CRL retrie val. • Click the Enable Lightweight Directory A ccess Protocol (LD AP) but ton to[...]

  • Page 6

    33-6 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Identity Certific ates Authentication T o avo id havi ng to retrie v e the same CRL from a CA repeatedly , The security appliance can store retrie ved CRLs local ly , which is called CRL caching. The CRL cache ca pacity varies b y platform[...]

  • Page 7

    33-7 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Identity Certificates Authentication Add/Install an Identity Certificate The Identity Certif icate panel lets you imp ort an exi sting identity certif icate from a file or add a ne w certificate conf iguration fr om an existing fi le. Cl[...]

  • Page 8

    33-8 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Identity Certific ates Authentication – The check box Include serial number of the de vice allo ws you to add the security appliance serial number t o the certif icate p arameters. – The Advanced > Enrollment M ode allo ws you to se[...]

  • Page 9

    33-9 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Identity Certificates Authentication • Issued to — Displays the X.50 0 fields o f the subject DN or certif icate owner and their v alues. This applies only to a v ailable stat us. • Issued by —Displays the X.500 fields of the ent[...]

  • Page 10

    33-10 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Identity Certific ates Authentication Generate Certificate Signin g Request This pane lets you generate a certif icate signin g request to send to En trust. Be aw are that at the ti me of this release, Entrust support s key mo dulus of si[...]

  • Page 11

    33-11 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Code-Signer Certificates To Add the Identity Certificate: Step 1 In the Identity Certificates panel , click the Add but t on . Step 2 In the Add Identity Cert if icate panel, select Add a new identity certif icate . Step 3 Optionally , [...]

  • Page 12

    33-12 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority • Delete an existing Identity Certificate. See Delete a Code-Signer Certificate . Export an e xisting Identity Certif icate. See Import or Export a Code-Si gner Certif icate . Show Code-Signer Certificate Det[...]

  • Page 13

    33-13 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority Note The local CA provides a certificat e authority on the adaptiv e secur ity appliance for use with SSL VPN connections, both brow ser - and client-based. User enrollment is by bro wser webpage login. The L[...]

  • Page 14

    33-14 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority Configuring the Local CA Sever The CA Serv er windo w lets you cust omize, modify , and control Local CA server operation. This section describes the parameters that can be specified. Additional paramete rs ar [...]

  • Page 15

    33-15 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority CA Server Key Size The CA Ke y Size parameter is the size of the used for the serv er certif icate generated fo r the Local CA server . Ke y size can be 512, 768, 1024, or 2048 bits per ke y . The default siz[...]

  • Page 16

    33-16 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority Publish CRL Interface and Port: T o make the CRL av ailable for HTTP do wnload on a gi ven interface or port. Sel ect an interface from the pull-do wn list. The opt ional port option can be an y port number in [...]

  • Page 17

    33-17 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority Enrollment Period The Enrollment Period field specif i es the number of hours an en roll ed user can retriev e a PKCS12 enrollment f ile in order to enroll and retri ev e a user certif icate. The enrollm ent [...]

  • Page 18

    33-18 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Manage User Certificates Manage User Certificates The Local CA server maintains certificate rene wals, re-issues user certificates, maintains t he Certificate Re vocation List (CRL), and rev o kes or restores pri vil eges as needed. With [...]

  • Page 19

    33-19 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Manage User Data base Email OTP The Email O TP butt on automatically send s an e-mail noti ce of enrollment permission with a unique one-time passwo rd (O TP) and th e Local CA enrollment w ebpage URL to the ne wly added u ser . Replace[...]

  • Page 20

    33-20 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Manage User Database[...]