06.05.2013 Views

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

ACS Certificate Setup<br />

9-22<br />

Step 1 In the navigation bar, click System Configuration.<br />

Step 2 Click Global Authentication Setup.<br />

The Global Authentications page appears.<br />

<strong>User</strong> <strong>Guide</strong> <strong>for</strong> <strong>Cisco</strong> <strong>Secure</strong> <strong>Access</strong> <strong>Control</strong> <strong>Server</strong> 4.2<br />

Chapter 9 System Configuration: Authentication and Certificates<br />

Step 3 Configure options, as applicable. For more in<strong>for</strong>mation about the significance of the options, see<br />

EAP-FAST Configuration Page, page 9-44.<br />

Step 4 If you want to immediately implement the settings that you have made, click Submit + Apply.<br />

ACS restarts its services and implements the authentication configuration options that you selected.<br />

Step 5 If you want to save the settings that you have made but implement them later, click Submit.<br />

ACS Certificate Setup<br />

Tip You can restart ACS services at any time by using the Service <strong>Control</strong> page in the System<br />

Configuration section.<br />

ACS saves the authentication configuration options that you selected.<br />

This section contains:<br />

Installing an ACS <strong>Server</strong> Certificate, page 9-22<br />

Adding a Certificate Authority Certificate, page 9-26<br />

Editing the Certificate Trust List, page 9-28<br />

Deleting a Certificate from the Certificate Trust List, page 9-29<br />

Managing Certificate Revocation Lists, page 9-29<br />

Generating a Certificate Signing Request, page 9-32<br />

Using Self-Signed Certificates, page 9-33<br />

Updating or Replacing an ACS Certificate, page 9-36<br />

Installing an ACS <strong>Server</strong> Certificate<br />

Per<strong>for</strong>m this procedure to install (that is, enroll) a server certificate <strong>for</strong> your ACS. You can per<strong>for</strong>m<br />

certificate enrollment to support EAP-TLS and PEAP authentication, as well as to support HTTPS<br />

protocol <strong>for</strong> GUI access to ACS.<br />

The three options <strong>for</strong> obtaining your server certificate are:<br />

Obtain a certificate from a CA.<br />

Use an existing certificate from local machine storage.<br />

Generate a self-signed certificate.<br />

OL-14386-02

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!