cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1510
Views
0
Helpful
7
Replies

how to set ios CA's expiration date 20 years?

asdg
Level 1
Level 1

when i set command "lifetime ca-certificate 7000",

the check command show error like this주석 2020-08-15 152843.png to me 

how can i set my ios CA's expiration date 20 years?

7 Replies 7

balaji.bandi
Hall of Fame
Hall of Fame

i do  believe it supports 10 years, 

 

PKI does not support a certificate with lifetime validity greater than the year 2099. So, It is recommended to choose a lifetime validity fewer than the value 2099.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

you mean 2099 days? i had confirmed that the pki router support expiration date more than 2099 days.

as per my knowledge that was information  i have,

to go deeper, can you provide the device model and version of code running on it.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

this is my ios image file:csr1000v-mono-universalk9.16.09.05.SPA.pkg
and result of "show version"
Cisco IOS XE Software, Version 16.09.05
Cisco IOS Software [Fuji], Virtual XE Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 16.9.5, RELEASE SOFTWARE (fc1)

router use csr1000v-mon-universalk9.16.09.05.SPA.pkg

Sorry, What I wanted was 20 years. i must modifiy the post.

@asdg 

You can define a lifetime of up to 7305 days (20 years) for the CA certificate.

 

crypto pki server PKI_SERVER
 lifetime ca-certificate 7305

Verification

csr_dc_2#show crypto pki certificates
CA Certificate
Status: Available
Certificate Serial Number (hex): 01
Certificate Usage: Signature
Issuer:
cn=LAB-PKI.lab.net
c=GB
Subject:
cn=LAB-PKI.lab.net
c=GB
Validity Date:
start date: 13:36:00 UTC Aug 15 2020
end date: 13:36:00 UTC Aug 15 2040
Associated Trustpoints: PKI_SERVER

I was using CSR 1000v 16.12.02

 

HTH

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: