We have a customer who has a Cisco VPN 3030 series concentrator.
Currently they do not support 4096 bit keys (we want to store a root CA cert that is 4096 bits).
Since the new ASA supports 4096 bit keys and there is a migration plan for VPN Concentrator users;
1. Will the VPN concentrator be made EOL or will there be further upgrades?
2. Will these upgrades if any support 4096 bit keys?
3. Is there any possibility of stopping verification of the certificate chain back to the root cert (All certs are 2048 bits or lower barr the root cert)?
4. If the customer has to upgrade is there a trade in plan?
http://www.cisco.com/en/US/products/ps6120/products_white_paper0900aecd80282f87.shtml
See here for support for 4096 bit keys
http://www.cisco.com/en/US/products/ps6120/products_data_sheets_list.html
ASA solution overview
http://www.cisco.com/univercd/cc/td/doc/product/multisec/asa_sw/v_70/migr_vpn/index.htm
Migrating from VPN 3000 concentrator