Chapter 5. Registration Authority
150
Note
Use the following command to retrieve the Cisco router IP address:
scep>show ip interface ethernet0/0
This command should return information similar to the following (irrelevant output has
been trimmed):
Ethernet0/0 is up, line protocol is up
Internet address is 10.14.1.94/24
Broadcast address is 255.255.255.255
Address determined by setup command
MTU is 1500 bytes
...
.../
Procedure 5.6. Approving the Certificate Request
After the certificate request has been received, it needs to be approved by the RA, which also provides
the one-time PIN to the router installer.
1. On the RA, navigate to the Agent interface and click
List Requests
.
2. Click the ID of the SCEP request that you want to approve.
3. Click
Approve
to approve the request.
This step produces an "Output" PIN. This is the password that you need to enter when performing
the "Crypto CA enroll CA" step on the router.
Procedure 5.7. Retrieving the Certificate and Enrolling
After the certificate request has been approved, and the RA has provided the one-time PIN, the Router
Administrator needs to go to the provided URL to complete the certificate enrollment.
1. On the RA, navigate to the End User interface. Click
SCEP Enrollment
, and then click
SCEP
Enrollment - Installer
.
2. The "SCEP enrollment URL for the router" is the URL you should enter at the
scep(config)
prompt when performing the "Crypto CA identity CA" step.
3. Log in to the router and proceed with the certificate enrollment. Refer to
Appendix C, Enrolling a
Certificate in a Cisco Router
for instructions on how to enroll the certificate.
5.3.3.2. Server Enrollment on an RA
Server Administrators use this page to submit a CSR for approval by an RA Agent. When the Agent
approves the request, an email notification is sent to the Server Administrator who can then retrieve
the server certificate.
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...