Manuale d’uso / di manutenzione del prodotto OL-16647-01 del fabbricante Cisco Systems
Vai alla pagina of 20
CH A P T E R 33-1 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 33 Configuring Certificates Digital certif icates provide digit al identif ication for authenti cation. A digital cert ificate contain s informa tion that id entifies a device or user , such as the name, serial number , compan y , department, or IP address.
33-2 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates CA Certificate Authentication • Add Button —Add a ne w certif icate conf igurat ion to the list. See Add/Install a CA Certif icate . • Edit Button —Modify an existing cert ificat e conf iguration.
33-3 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates CA Certificate Authentication More Options... —F or additional op tions for ne w certif icates, click the Mor e Options... button to display conf iguration opti ons for ne w and existi ng certifi cates.
33-4 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates CA Certificate Authentication Configuration Options for CA Certi ficates Additional conf .
33-5 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates CA Certificate Authentication CRL Retrieval Method Configuration The CRL Retri ev a l Method pan el lets yo u select the method to be used for CRL retrie val.
33-6 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Identity Certific ates Authentication T o avo id havi ng to retrie v e the same CRL from a CA repeatedly , The security appliance can store retrie ved CRLs local ly , which is called CRL caching.
33-7 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Identity Certificates Authentication Add/Install an Identity Certificate The Identity Certif icate panel lets you imp ort an exi sting identity certif icate from a file or add a ne w certificate conf iguration fr om an existing fi le.
33-8 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Identity Certific ates Authentication – The check box Include serial number of the de vice allo ws you to add the security appliance serial number t o the certif icate p arameters.
33-9 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Identity Certificates Authentication • Issued to — Displays the X.50 0 fields o f the subject DN or certif icate owner and their v alues.
33-10 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Identity Certific ates Authentication Generate Certificate Signin g Request This pane lets you generate a certif icate signin g request to send to En trust.
33-11 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Code-Signer Certificates To Add the Identity Certificate: Step 1 In the Identity Certificates panel , click the Add but t on . Step 2 In the Add Identity Cert if icate panel, select Add a new identity certif icate .
33-12 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority • Delete an existing Identity Certificate. See Delete a Code-Signer Certificate . Export an e xisting Identity Certif icate.
33-13 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority Note The local CA provides a certificat e authority on the adaptiv e secur ity appliance for use with SSL VPN connections, both brow ser - and client-based.
33-14 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority Configuring the Local CA Sever The CA Serv er windo w lets you cust omize, modify , and control Local CA server operation.
33-15 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority CA Server Key Size The CA Ke y Size parameter is the size of the used for the serv er certif icate generated fo r the Local CA server .
33-16 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority Publish CRL Interface and Port: T o make the CRL av ailable for HTTP do wnload on a gi ven interface or port. Sel ect an interface from the pull-do wn list.
33-17 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority Enrollment Period The Enrollment Period field specif i es the number of hours an en roll ed user can retriev e a PKCS12 enrollment f ile in order to enroll and retri ev e a user certif icate.
33-18 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Manage User Certificates Manage User Certificates The Local CA server maintains certificate rene wals, re-issues user certificates, maintains t he Certificate Re vocation List (CRL), and rev o kes or restores pri vil eges as needed.
33-19 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Manage User Data base Email OTP The Email O TP butt on automatically send s an e-mail noti ce of enrollment permission with a unique one-time passwo rd (O TP) and th e Local CA enrollment w ebpage URL to the ne wly added u ser .
33-20 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Manage User Database.
Un punto importante, dopo l’acquisto del dispositivo (o anche prima di acquisto) è quello di leggere il manuale. Dobbiamo farlo per diversi motivi semplici:
Se non hai ancora comprato il Cisco Systems OL-16647-01 è un buon momento per familiarizzare con i dati di base del prodotto. Prime consultare le pagine iniziali del manuale d’uso, che si trova al di sopra. Dovresti trovare lì i dati tecnici più importanti del Cisco Systems OL-16647-01 - in questo modo è possibile verificare se l’apparecchio soddisfa le tue esigenze. Esplorando le pagine segenti del manuali d’uso Cisco Systems OL-16647-01 imparerai tutte le caratteristiche del prodotto e le informazioni sul suo funzionamento. Le informazioni sul Cisco Systems OL-16647-01 ti aiuteranno sicuramente a prendere una decisione relativa all’acquisto.
In una situazione in cui hai già il Cisco Systems OL-16647-01, ma non hai ancora letto il manuale d’uso, dovresti farlo per le ragioni sopra descritte. Saprai quindi se hai correttamente usato le funzioni disponibili, e se hai commesso errori che possono ridurre la durata di vita del Cisco Systems OL-16647-01.
Tuttavia, uno dei ruoli più importanti per l’utente svolti dal manuale d’uso è quello di aiutare a risolvere i problemi con il Cisco Systems OL-16647-01. Quasi sempre, ci troverai Troubleshooting, cioè i guasti più frequenti e malfunzionamenti del dispositivo Cisco Systems OL-16647-01 insieme con le istruzioni su come risolverli. Anche se non si riesci a risolvere il problema, il manuale d’uso ti mostrerà il percorso di ulteriori procedimenti – il contatto con il centro servizio clienti o il servizio più vicino.