SCEP Setup
Simple Certificate Enrollment Protocol (SCEP) is the standard for automatically provisioning and renewing
certificates. It avoids manual installation of certificates on your phones.
Configure the SCEP Product Specific Configuration Parameters
You must configure the following SCEP parameters on your phone web page
•
RA IP address
•
SHA-1 or SHA-256 fingerprint of the root CA certificate for the SCEP server
The Cisco IOS Registration Authority (RA) serves as a proxy to the SCEP server. The SCEP client on the
phone use the parameters that are downloaded from Cisco Unified Communication Manager. After you
configure the parameters, the phone sends a
SCEP getcs
request to the RA and the root CA certificate is
validated using the defined fingerprint.
Procedure
Step 1
From the Cisco Unified Communications Manager Administration, select
Device
>
Phone
.
Step 2
Locate the phone.
Step 3
Scroll to the
Product Specific Configuration Layout
area.
Step 4
Check the
WLAN SCEP Server
check box to activate the SCEP parameter.
Step 5
Check the
WLAN Root CA Fingerprint (SHA256 or SHA1)
check box to activate the SCEP QED parameter.
Simple Certificate Enrollment Protocol Server Support
If you are using a Simple Certificate Enrollment Protocol (SCEP) server, the server can automatically maintain
your user and server certificates. On the SCEP server, configure the SCEP Registration Agent (RA) to:
•
Act as a PKI trust point
•
Act as a PKI RA
•
Perform device authentication using a RADIUS server
For more information, see your SCEP server documentation.
802.1X Authentication
The Cisco IP Phones support 802.1X Authentication.
Cisco IP Phones and Cisco Catalyst switches traditionally use Cisco Discovery Protocol (CDP) to identify
each other and determine parameters such as VLAN allocation and inline power requirements. CDP does not
identify locally attached workstations. Cisco IP Phones provide an EAPOL pass-through mechanism. This
mechanism allows a workstation attached to the Cisco IP Phone to pass EAPOL messages to the 802.1X
authenticator at the LAN switch. The pass-through mechanism ensures that the IP phone does not act as the
LAN switch to authenticate a data endpoint before accessing the network.
Cisco IP Phones also provide a proxy EAPOL Logoff mechanism. In the event that the locally attached PC
disconnects from the IP phone, the LAN switch does not see the physical link fail, because the link between
Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager
108
Supported Security Features
Summary of Contents for 8865
Page 23: ...P A R T I About the Cisco IP Phone Technical Details page 7 Cisco IP Phone Hardware page 23 ...
Page 24: ......
Page 54: ......
Page 100: ......
Page 218: ......