Appendix C. Enrolling a Certificate in a Cisco Router
510
scep(config)# crypto ca trusted-root 1
scep(ca-root)# root CEP http://paw.sfbay.redhat.com:12888/ee/scep/pkiclient.cgi
scep(ca-root)# crl optional
scep(ca-root)# exit
scep(config)# cry ca authenticate 1
scep(config)# crypto ca trusted-root 0
scep(ca-root)# root CEP http://paw.sfbay.redhat.com:12888/ee/scep/pkiclient.cgi
scep(ca-root)# crl optional
scep(ca-root)# exit
scep(config)# cry ca authenticate 0
In the above example, if your CA certs do not have CRL distribution point extension in them, you must
turn off the CRL requirement:
scep(ca-root)# crl optional
Set up a CA identity:
scep(config)# crypto ca identity CA
scep(ca-identity)# enrollment url http://paw.sfbay.redhat.com:12888/ee/scep/pkiclient.cgi
scep(ca-identity)# crl optional
scep(ca-identity)# exit
Submit enrollment request to subordinate CA in this example:
scep(config)# crypto ca authenticate CA
scep(config)# crypto ca enroll CA
C.2.2. DEBUGGING:
The router will provide additional debugging during SCEP operations if you execute the following
debug statements.
scep# debug crypto pki callbacks
Crypto PKI callbacks debugging is on
scep# debug crypto pki messages
Crypto PKI Msg debugging is on
scep# debug crypto pki transactions
Crypto PKI Trans debugging is on
scep# debug crypto verbose
verbose debug output debugging is on
Содержание CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 7 3 Administration Guide Publication date May 2007 updated March 25 2010 ...
Страница 15: ...xv Index 525 ...
Страница 16: ...xvi ...
Страница 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Страница 154: ...132 ...
Страница 194: ...172 ...
Страница 238: ...216 ...
Страница 244: ...222 ...
Страница 246: ...224 ...
Страница 286: ...264 ...
Страница 292: ...270 ...
Страница 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Страница 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Страница 371: ...Configuring Mappers 349 Figure 15 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 398: ...376 ...
Страница 412: ...390 ...
Страница 472: ...450 ...
Страница 500: ...Appendix A Certificate and CRL Extensions 478 Parameter namen Table A 8 IssuerAlternativeName Configuration Parameters ...
Страница 506: ...484 ...
Страница 528: ...506 ...
Страница 546: ...524 ...