cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1981
Views
0
Helpful
7
Replies

how to set ios CA's expiration date 20 years?

asdg
Level 1
Level 1

when i set command "lifetime ca-certificate 7000",

the check command show error like this주석 2020-08-15 152843.png to me 

how can i set my ios CA's expiration date 20 years?

7 Replies 7

balaji.bandi
Hall of Fame
Hall of Fame

i do  believe it supports 10 years, 

 

PKI does not support a certificate with lifetime validity greater than the year 2099. So, It is recommended to choose a lifetime validity fewer than the value 2099.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

you mean 2099 days? i had confirmed that the pki router support expiration date more than 2099 days.

as per my knowledge that was information  i have,

to go deeper, can you provide the device model and version of code running on it.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

this is my ios image file:csr1000v-mono-universalk9.16.09.05.SPA.pkg
and result of "show version"
Cisco IOS XE Software, Version 16.09.05
Cisco IOS Software [Fuji], Virtual XE Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 16.9.5, RELEASE SOFTWARE (fc1)

router use csr1000v-mon-universalk9.16.09.05.SPA.pkg

Sorry, What I wanted was 20 years. i must modifiy the post.

@asdg 

You can define a lifetime of up to 7305 days (20 years) for the CA certificate.

 

crypto pki server PKI_SERVER
 lifetime ca-certificate 7305

Verification

csr_dc_2#show crypto pki certificates
CA Certificate
Status: Available
Certificate Serial Number (hex): 01
Certificate Usage: Signature
Issuer:
cn=LAB-PKI.lab.net
c=GB
Subject:
cn=LAB-PKI.lab.net
c=GB
Validity Date:
start date: 13:36:00 UTC Aug 15 2020
end date: 13:36:00 UTC Aug 15 2040
Associated Trustpoints: PKI_SERVER

I was using CSR 1000v 16.12.02

 

HTH