Configuration Guide
7. IPSec Tunneling
Version 7.2
43
Security Setup
7.1.3.1.4 Import Device Certificate Using Signing Request
1.
Go to the PKI CLI section:
#configure data
MSBR(config-data)#crypto isakmp
2.
Create certificate fields names, such as country codes, state, Organization name etc
using the command "certificate subject field-set <FIELD NAME> <FIELD VALUE>":
(config-isakmp-pki)#certificate subject field-set organization
AC
(config-isakmp-pki)#certificate subject field-set country IL
(config-isakmp-pki)#certificate subject field-set common-name
MSBR-7
3.
Generate a signing request:
(config-isakmp-pki)#certificate signing-request
Certificate signing request:
-----BEGIN CERTIFICATE REQUEST-----
MIICgTCC…
---output omitted---
…zxcsF
-----END CERTIFICATE REQUEST-----
Send this request to your security administrator for signing,
then upload the new signed certificate to the device.
4.
Using the signing request, obtain the device certificate and then import the obtained
certificate using the import command "Certificate import".
(config-isakmp-pki)#certificate import
Enter data below. Type a period (.) on an empty line to
finish.
-----BEGIN CERTIFICATE-----
MIIEoDCCAoigAwIB
---output omitted---
-----END CERTIFICATE-----
.
File replaced.
MSBR(config-isakmp-pki)#
5.
Check if the imported certificate matches the private key with which it was generated:
MSBR-31(config-isakmp-pki)# certificate status
Certificate subject: /C=IL/CN=MSBR-31
Certificate issuer :
/C=IL/ST=CENTER/L=LOD/O=Audiocodes/OU=R&D/CN=ca.local/emailAdd
Signature Algorithm: sha256WithRSAEncryption
Time to expiration : 369 days
Key size: 2048 bits
Active sockets: 0
The currently-loaded private
key matches
this certificate.
Summary of Contents for Mediant 500L MSBR
Page 2: ......
Page 4: ...Mediant MSBRs 4 Document LTRT 31828 Security Setup This page is intentionally left blank...
Page 8: ...Mediant MSBRs 8 Document LTRT 31828 Security Setup This page is intentionally left blank...
Page 12: ...Mediant MSBRs 12 Document LTRT 31828 Security Setup This page is intentionally left blank...
Page 16: ...Mediant MSBRs 16 Document LTRT 31828 Security Setup This page is intentionally left blank...
Page 18: ...Mediant MSBRs 18 Document LTRT 31828 Security Setup This page is intentionally left blank...
Page 24: ...Mediant MSBRs 24 Document LTRT 31828 Security Setup This page is intentionally left blank...
Page 28: ...Mediant MSBRs 28 Document LTRT 31828 Security Setup This page is intentionally left blank...
Page 54: ...Mediant MSBRs 54 Document LTRT 31828 Security Setup This page is intentionally left blank...
Page 62: ...Mediant MSBRs 62 Document LTRT 31828 Security Setup This page is intentionally left blank...
Page 72: ...Mediant MSBRs 72 Document LTRT 31828 Security Setup This page is intentionally left blank...