Cisco C3201FESMIC-TP= - 3201 Fast EN Switch Mobile Interface Card Expansion Module Software Configuration Manual page 197

Wireless mic
Table of Contents

Advertisement

Authentication Types
Enter configuration commands, one per line.
maldives-ap(config)#crypto pki trustpoint TEST-SCEP
maldives-ap(ca-trustpoint)#enrollment url http://10.67.73.11/certsrv/mscep/mscep.dll
maldives-ap(ca-trustpoint)#rsakeypair scep-keys 1024
maldives-ap(ca-trustpoint)#exit
maldives-ap(config)#
!
maldives-ap#show run
...
crypto pki trustpoint TEST-SCEP
enrollment mode ra
enrollment url http://10.67.73.11:80/certsrv/mscep/mscep.dll
serial-number
ip-address BVI1
revocation-check crl
rsakeypair scep-keys 1024
!
And to retrieve the CA certificate:
maldives-ap(config)#crypto pki authenticate TEST-SCEP
Certificate has the following attributes:
Fingerprint: 45EC6866 A66B4D8F 2E05960F BC5C1B76
% Do you accept this certificate? [yes/no]: yes
Trustpoint CA certificate accepted.
maldives-ap(config)#
Finally to enroll the router certificate(s):
maldives-ap(config)#
maldives-ap(config)#crypto pki enroll TEST-SCEP
%
% Start certificate enrollment..
% Create a challenge password. You will need to verbally provide this
password to the CA Administrator in order to revoke your certificate.
For security reasons your password will not be saved in the configuration.
Please make a note of it.
Password:
Jun 29 13:18:46.606: %CRYPTO-6-AUTOGEN: Generated new 1024 bit key pair
Re-enter password:
% The fully-qualified domain name in the certificate will be: maldives-ap.cisco.com
% The subject name in the certificate will be: maldives-ap.cisco.com
% Include the router serial number in the subject name? [yes/no]: yes
% The serial number in the certificate will be: 80AD5AD4
% Include an IP address in the subject name? [no]: yes
Enter Interface name or IP Address[]: BVI1
Request certificate from CA? [yes/no]: yes
% Certificate request sent to Certificate Authority
% The certificate request fingerprint will be displayed.
maldives-ap(config)#
Jun 29 13:19:12.776: CRYPTO_PKI:
Jun 29 13:19:12.776:
Jun 29 13:19:15.161: %PKI-6-CERTRET: Certificate received from Certificate Authority
maldives-ap(config)# end
The crypto show commands are used to view the certificates associated with the trustpoint,
in this case both the CA and single router certificate:
maldives-ap#show crypto pki cert TEST-SCEP
Configuring Certificates Using the crypto pki CLI
End with CNTL/Z.
Fingerprint:
6BF9EAC9 BE515B76 E7767395 8FA00FCC
Cisco 3200 Series Wireless MIC Software Configuration Guide
13

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents