Authentication Types
Configuring Certificates Using the crypto pki CLI
12
Cisco 3200 Series Wireless MIC Software Configuration Guide
The following example shows the TFTP configuration method:
maldives-ap#show run
...
crypto pki trustpoint TEST-TFTP
enrollment url tftp://10.67.64.21/ndupreez/my-acs
revocation-check crl
rsakeypair 1024
Configuration Using SCEP
Configuration using Certificate Enrollment Protocol (SCEP) is available when a Windows 2003 server
is used as the CA server, and is a convenient way of importing CA and router certificates. Follow these
steps to use SCEP:
Tip
You can install the SCEP Add-on for Windows 2003 server from the following link:
http://www.microsoft.com/downloads/details.aspx?displaylang=en&familyid=9f306763-d036-41d8-88
60-1636411b2d01
It is recommended that you use Windows Server 2003 Enterprise Edition as the Windows operating
system when SCEP is selected to acquire a certificate under the Enterprise Certificate Server (CA) mode
for the Windows CA server that works with the Cisco ACS server. Windows Server 2003 Enterprise
Edition allows the modification of the CA server template. For use of SCEP with the Enterprise CA
server, you must modify the IPSec template (offline request) so that its enhanced key usage extension is
same as that for the user template. Use certtmpl.msc to modify the template and ertsrv.msc to install the
modified template.
The following example shows SCEP certificate enrollment:
maldives-ap#
maldives-ap#conf t
Command
Purpose
Step 1
configure terminal
Enters global configuration mode.
Step 2
crypto pki trustpoint
name
Specifies the name of the trustpoint.
Step 3
enrollment url
http://address
Specifies the URL to be used for certificate enrollment.
Step 4
rsakeypair
name
1024
Specifies that a scep key is will be generated with length 1024.
Step 5
subject-name CN=
name
Adds the subject name in the certificate. The name should be
same as the user name defined in the
dot1x credentials
name
command.
Step 6
exit
Returns to global configuration mode.
Step 7
crypto pki authenticate
name
Enters the process of importing the CA certificate.
Step 8
crypto pki enroll
name
Requests a router certificate from a CA. This step generates the
certificate request and puts it onto TFTP server. This request
should then be copied on to CA server to receive router
certificate.
Step 9
end
Ends EXEC mode.
Step 10
copy running-config startup-config
(Optional) Saves your entries in the configuration file.
Содержание 3200 Series
Страница 14: ...xiv Cisco 3200 Series Wireless MIC Software Configuration Guide OL 6415 04 ...
Страница 120: ...Administering the WMIC Managing the System Time and Date 56 Cisco 3200 Series Wireless MIC Software Configuration Guide ...
Страница 136: ...Dynamic Frequency Selection Additional Information 6 Radio Channels and Transmit Frequencies OL 11491 03 ...
Страница 254: ...WIMIC Troubleshooting Error and Event Messages 12 Cisco 3200 Series Wireless MIC Software Configuration Guide ...
Страница 272: ...Supported MIBs Using FTP to Access the MIB Files 4 Cisco 3200 Series Wireless MIC Software Configuration Guide ...
Страница 314: ...Index IN 12 Cisco 3200 Series Wireless MIC Software Configuration Guide OL 6415 04 ...