Cisco SystemsメーカーOL-16647-01の使用説明書/サービス説明書
ページ先へ移動 of 20
CH A P T E R 33-1 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 33 Configuring Certificates Digital certif icates provide digit al identif ication for authenti cation. A digital cert ificate contain s informa tion that id entifies a device or user , such as the name, serial number , compan y , department, or IP address.
33-2 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates CA Certificate Authentication • Add Button —Add a ne w certif icate conf igurat ion to the list. See Add/Install a CA Certif icate . • Edit Button —Modify an existing cert ificat e conf iguration.
33-3 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates CA Certificate Authentication More Options... —F or additional op tions for ne w certif icates, click the Mor e Options... button to display conf iguration opti ons for ne w and existi ng certifi cates.
33-4 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates CA Certificate Authentication Configuration Options for CA Certi ficates Additional conf .
33-5 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates CA Certificate Authentication CRL Retrieval Method Configuration The CRL Retri ev a l Method pan el lets yo u select the method to be used for CRL retrie val.
33-6 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Identity Certific ates Authentication T o avo id havi ng to retrie v e the same CRL from a CA repeatedly , The security appliance can store retrie ved CRLs local ly , which is called CRL caching.
33-7 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Identity Certificates Authentication Add/Install an Identity Certificate The Identity Certif icate panel lets you imp ort an exi sting identity certif icate from a file or add a ne w certificate conf iguration fr om an existing fi le.
33-8 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Identity Certific ates Authentication – The check box Include serial number of the de vice allo ws you to add the security appliance serial number t o the certif icate p arameters.
33-9 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Identity Certificates Authentication • Issued to — Displays the X.50 0 fields o f the subject DN or certif icate owner and their v alues.
33-10 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Identity Certific ates Authentication Generate Certificate Signin g Request This pane lets you generate a certif icate signin g request to send to En trust.
33-11 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Code-Signer Certificates To Add the Identity Certificate: Step 1 In the Identity Certificates panel , click the Add but t on . Step 2 In the Add Identity Cert if icate panel, select Add a new identity certif icate .
33-12 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority • Delete an existing Identity Certificate. See Delete a Code-Signer Certificate . Export an e xisting Identity Certif icate.
33-13 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority Note The local CA provides a certificat e authority on the adaptiv e secur ity appliance for use with SSL VPN connections, both brow ser - and client-based.
33-14 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority Configuring the Local CA Sever The CA Serv er windo w lets you cust omize, modify , and control Local CA server operation.
33-15 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority CA Server Key Size The CA Ke y Size parameter is the size of the used for the serv er certif icate generated fo r the Local CA server .
33-16 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority Publish CRL Interface and Port: T o make the CRL av ailable for HTTP do wnload on a gi ven interface or port. Sel ect an interface from the pull-do wn list.
33-17 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Local Certificate Authority Enrollment Period The Enrollment Period field specif i es the number of hours an en roll ed user can retriev e a PKCS12 enrollment f ile in order to enroll and retri ev e a user certif icate.
33-18 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Manage User Certificates Manage User Certificates The Local CA server maintains certificate rene wals, re-issues user certificates, maintains t he Certificate Re vocation List (CRL), and rev o kes or restores pri vil eges as needed.
33-19 Cisco Security Applia nce Command Line Configuratio n Guide OL-16647-01 Chapter 33 Configuring Certificates Manage User Data base Email OTP The Email O TP butt on automatically send s an e-mail noti ce of enrollment permission with a unique one-time passwo rd (O TP) and th e Local CA enrollment w ebpage URL to the ne wly added u ser .
33-20 Cisco Security Appliance Command Line Configuration Guide OL-16647-01 Chapter 33 Configuring Certificates Manage User Database.
デバイスCisco Systems OL-16647-01の購入後に(又は購入する前であっても)重要なポイントは、説明書をよく読むことです。その単純な理由はいくつかあります:
Cisco Systems OL-16647-01をまだ購入していないなら、この製品の基本情報を理解する良い機会です。まずは上にある説明書の最初のページをご覧ください。そこにはCisco Systems OL-16647-01の技術情報の概要が記載されているはずです。デバイスがあなたのニーズを満たすかどうかは、ここで確認しましょう。Cisco Systems OL-16647-01の取扱説明書の次のページをよく読むことにより、製品の全機能やその取り扱いに関する情報を知ることができます。Cisco Systems OL-16647-01で得られた情報は、きっとあなたの購入の決断を手助けしてくれることでしょう。
Cisco Systems OL-16647-01を既にお持ちだが、まだ読んでいない場合は、上記の理由によりそれを行うべきです。そうすることにより機能を適切に使用しているか、又はCisco Systems OL-16647-01の不適切な取り扱いによりその寿命を短くする危険を犯していないかどうかを知ることができます。
ですが、ユーザガイドが果たす重要な役割の一つは、Cisco Systems OL-16647-01に関する問題の解決を支援することです。そこにはほとんどの場合、トラブルシューティング、すなわちCisco Systems OL-16647-01デバイスで最もよく起こりうる故障・不良とそれらの対処法についてのアドバイスを見つけることができるはずです。たとえ問題を解決できなかった場合でも、説明書にはカスタマー・サービスセンター又は最寄りのサービスセンターへの問い合わせ先等、次の対処法についての指示があるはずです。