Hello,
a rather complete guide for dealing with certificates in a VPN concentratot is found in "Certificate Management" at http://www.cisco.com/en/US/products/hw/vpndevc/ps2284/products_administration_guide_chapter09186a00803ef352.html
In the text it gives (hopefully) an answer to your question:
"Challenge Password — Use this field according to the policy of your CA:
–Your CA might have given you a password. If so, enter it here for authentication.
–Your CA might allow you to provide your own password to identify yourself to the CA in the future. If so, create your password here.
–Your CA might not require a password. If not, leave this field blank.
Note This field (and the Verify Challenge Password field) display if you are requesting a certificate using SCEP. This field does not apply to manual certificate requests."
So depending on your certificate you can leave it empty or define it here or have to match a preset password during CA creation.
Hope this helps! Please rate all posts.
Regards, Martin