Enrolling a Certificate on a Cisco Router
85
Option
Description
-k
The key type to use; the only native option is
rsa
. If the CA is ECC-enabled (described in the
Installation Guide
),
then this can also be
ec
.
-g
The key size. The recommended size for RSA keys is 2048 and for ECC, 256.
-s
The subject name of the certificate.
NOTE
Certificate System supports all UTF-8 characters for the common name and organizational unit elements
included in the subject name of the certificate.
-o
The output file to which to save the certificate request.
-v
The validity period, in months.
-d
Certificate database directory; this is the directory for the subsystem instance.
numbers 1-8
These set the available certificate extensions. Only eight can be specified through the
certutil
tool:
• Key Usage: 1
• Basic Constraints: 2
• Certificate Authority Key ID: 3
• CRL Distribution Point: 4
• Netscape Certificate Type: 5
• Extended Key Usage: 6
• Email Subject Alternative Name: 7
• DNS Subject Alternative Name: 8
-a
Outputs the certificate request to an ASCII file instead of binary.
Table 4.1. Options for Requesting Certificates with certutil
4.4. Enrolling a Certificate on a Cisco Router
Simple Certificate Enrollment Protocol (SCEP), designed by Cisco, is a way for a router to
communicate a certificate issuing authority (like a CA or RA) to enroll certificates for the router.
Normally, a router installer enters the RA's URL and a challenge password (also called a one-time
PIN) into the router and issues a command to initiate the enrollment. The router then communicates
with the RA over SCEP to generate and request the certificate and then to retrieve it. The router can
also check the status of a pending request using SCEP.
NOTE
SCEP defines two ways for submitting a certificate request, either to an RA or to a CA.
In Certificate System, the RA does not have a signing certificate, so SCEP certificates
are always issued and signed with the CA signing certificate, even if they are submitted
through the RA.
Содержание CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 8 0 Admin Guide Publication date July 22 2009 updated on March 25 2010 ...
Страница 42: ...20 ...
Страница 43: ...Part I Setting up Certificate Services ...
Страница 44: ......
Страница 190: ...168 ...
Страница 208: ...186 ...
Страница 223: ...Part II Additional Configuration to Manage CA Services ...
Страница 224: ......
Страница 256: ...234 ...
Страница 270: ...248 ...
Страница 280: ...258 ...
Страница 292: ...270 ...
Страница 293: ...Part III Managing the Subsystem Instances ...
Страница 294: ......
Страница 363: ...Managing RA Users 341 5 The user details page shows the person s UID full name email address and user SSL certificate ...
Страница 408: ...386 ...
Страница 438: ...416 ...
Страница 439: ...Part IV References ...
Страница 440: ......
Страница 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Страница 504: ...482 ...
Страница 556: ...534 ...
Страница 564: ...542 ...