<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic When  is the CA server necesaary? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/when-is-the-ca-server-necesaary/m-p/2389171#M920050</link>
    <description>&lt;P&gt;Hi:&lt;/P&gt;&lt;P&gt;I have&amp;nbsp; a hub and spoke network with PKI based security.&amp;nbsp; My question is , during normal operations , after certificates after been issued and the spoke routers have SA associations set up, are&amp;nbsp; there any more&amp;nbsp; communications with the CA server? Assuming that the hub and spoke routers&amp;nbsp; are constantly communicating is there a need for the CA server? Even is the communication between&amp;nbsp; a hub router a spoke router have to be renewed, is the CA server involved? As long as the certificates don't expire, is the CA server involved?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mickey&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 13:02:17 GMT</pubDate>
    <dc:creator>mikik</dc:creator>
    <dc:date>2020-02-21T13:02:17Z</dc:date>
    <item>
      <title>When  is the CA server necesaary?</title>
      <link>https://community.cisco.com/t5/network-security/when-is-the-ca-server-necesaary/m-p/2389171#M920050</link>
      <description>&lt;P&gt;Hi:&lt;/P&gt;&lt;P&gt;I have&amp;nbsp; a hub and spoke network with PKI based security.&amp;nbsp; My question is , during normal operations , after certificates after been issued and the spoke routers have SA associations set up, are&amp;nbsp; there any more&amp;nbsp; communications with the CA server? Assuming that the hub and spoke routers&amp;nbsp; are constantly communicating is there a need for the CA server? Even is the communication between&amp;nbsp; a hub router a spoke router have to be renewed, is the CA server involved? As long as the certificates don't expire, is the CA server involved?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mickey&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:02:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/when-is-the-ca-server-necesaary/m-p/2389171#M920050</guid>
      <dc:creator>mikik</dc:creator>
      <dc:date>2020-02-21T13:02:17Z</dc:date>
    </item>
    <item>
      <title>When  is the CA server necesaary?</title>
      <link>https://community.cisco.com/t5/network-security/when-is-the-ca-server-necesaary/m-p/2389172#M920051</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In general, the CA is only needed when a new certificate has to be issued. The normal IPSec-tunnel-setup doesn't need the CA at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But: When the tunnel-setup is done, the hub (or even both hub and spoke) can be configured to compare the serial-number of the presented certificate against a list of revoked certificates (a CRL, Certificate Revocation List). Although not a best practice, this list is often served by the CA. If your PKI is configured that way, then the CA has to be online all the time. If best practice was followed while setting up the CA, the CRL is published to a different server and the CA only has to be online when new certificates are issued or a new CRL is published. Here the server hosting the CRL has to be online all the time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Similar concept, instead of a CRL you could use the Online Certificate Status Protolol (OCSP), but here is the same, instead of running that service on the CA it's better to use a different system for that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Nov 2013 22:02:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/when-is-the-ca-server-necesaary/m-p/2389172#M920051</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-11-10T22:02:30Z</dc:date>
    </item>
    <item>
      <title>When  is the CA server necesaary?</title>
      <link>https://community.cisco.com/t5/network-security/when-is-the-ca-server-necesaary/m-p/2389173#M920052</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the answer. This is also my understanding but was not sure. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mickey&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Nov 2013 06:39:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/when-is-the-ca-server-necesaary/m-p/2389173#M920052</guid>
      <dc:creator>mikik</dc:creator>
      <dc:date>2013-11-11T06:39:05Z</dc:date>
    </item>
  </channel>
</rss>

