Using the End Users Services Interface
149
5.3.3.1.1. Configuration
CA Configuration
If the router communicates directly with the CA, the administrator must add the following to the
/var/
lib/rhpki-ca/conf/flatfile.txt
file (one-time PIN file) on the CA:
UID:
<IP address of the router>
PWD:
<One-time PIN>
For example:
UID:172.16.24.238
PWD:1212
Note
If the router communicates directly with the RA, the above configuration is not required.
RA Configuration
On the RA, the PIN is generated when the request is approved, and stored in the SQLite database.
Consequently, no configuration is required.
Procedure 5.5. Submitting the certificate request
After the CA and the RA have been installed and appropriately configured, the Router Administrator
submits the certificate request.
1. On the RA, navigate to the SSL End Users Services page, and then click
SCEP Enrollment
.
2. Click
Request Submission - Manager
3. Enter the following information:
• Client ID: cisco1
• Site ID:
<site IP address>
• Your mail:
. This is the address to which the certificate approval
notice will be sent.
4. Click
Submit
. You should see a response similar to the following:
Your request has been successfully submitted.
Request ID: 1
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...