The certificates or shared secrets are only used for Phase 1 SA negotiation. You'll still need to use a username or password for secondary authentication (via local, radius, etc).
Your post isn't very clear on what you are trying to achieve - Can you post more specifics?
Our environment has multiple sites using PIX's with a centralized Microsoft CA server. If you choose to go this route I'll be more than happy to help you with setup\config.
On your revocation question - the PIX verifies validity based on the certificate being signed by the CA. The PIX also checks the CRL list from the CA server for revocations and will deny access if it is included in the list.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.