Chapter 4. Requesting, Enrolling, and Managing Certificates
90
scep(ca-identity)# enrollment url http://server.example.com:12888/ee/scep/pkiclient.cgi
scep(ca-identity)# crl optional
4.4.4. Re-enrolling a Router
Before a router can be re-enrolled with new certificates, the existing configuration has to be removed.
1. Remove (zeroize) the existing keys.
scep(config)# crypto key zeroize rsa
% Keys to be removed are named scep.server.example.com.
Do you really want to remove these keys? [yes/no]: yes
2. Remove the CA identity.
scep(config)# no crypto ca identity CA
% Removing an identity will destroy all certificates received from
the related Certificate Authority.
Are you sure you want to do this? [yes/no]: yes
% Be sure to ask the CA administrator to revoke your certificates.
No enrollment sessions are currently active.
4.4.5. Enabling Debugging
The router provides additional debugging during SCEP operations by enabling the debug statements.
scep# debug crypto pki callbacks
Crypto PKI callbacks debugging is on
scep# debug crypto pki messages
Crypto PKI Msg debugging is on
scep# debug crypto pki transactions
Crypto PKI Trans debugging is on
scep#debug crypto verbose
verbose debug output debugging is on
4.5. Performing Bulk Issuance
There can be instances when an administrator needs to submit and generate a large number of
certificates simultaneously, such as provisioning a new lot of HSMs or servers. Certificate System
provides a bulk issuance tool (
bulkissuance
) which submits a file that can contain dozens, even
thousands, of certificate requests to a special agent's interface for the CA. The file is essentially
composed like an HTML POST that can be parsed by the CA.
NOTE
The bulk issuance tool helps to
process
certificate requests. It does not
generate
certificate requests, so all key generate and certificate request generation must be done
before performing a bulk issuance.
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...