Try this link from Cisco
"By default, the security appliance has a self-signed certificate that is regenerated every time the device is rebooted. You can purchase your own certificate from vendors, such as Verisign or EnTrust, or you can configure the ASA to issue an identity certificate to itself. This certificate remains the same even when the device is rebooted. Complete this step in order to generate a self-issued certificate that persists when the device is rebooted....."
http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00808efbd2.shtml