Certificate Enrollment Using Scep - Avaya 1000 Series Configuration Manual

Secure router
Hide thumbs Also See for 1000 Series:
Table of Contents

Advertisement

PKI Certificate Support

Certificate enrollment using SCEP

1. Create a trustpoint.
2. Configure the enrollment URL.
3. Configure the subject name, ip address, fqdn, email address and key pair details.
4. Fetch the Certificate Authority (CA) Certificate.
5. Generate the Certificate request, send it to CA and import the certificate. Since here
174
Avaya Secure Router 1000 Series Configuration Guide
R1/configure> ca trustpoint ms2003
R1/configure/crypto/ca/trustpoint ms2003> enrollment url
http://192.168.114.2/certsrv/mscep/mscep.dll/
• R1/configure/crypto/ca/trustpoint ms2003> subject-name
cn=orion,ou=security,o=tasmannetworks,c=us
• R1/configure/crypto/ca/trustpoint ms2003> ip-address
10.1.1.1
• R1/configure/crypto/ca/trustpoint ms2003> fqdn
tasmannetworks.com
• R1/configure/crypto/ca/trustpoint ms2003> email
test@test.com
• R1/configure/crypto/ca/trustpoint ms2003> keypair key1
rsa 1024
R1/configure/crypto> ca authenticate ms2003
Finger print is computed on the CA certificate, and displayed to the user.
the enrollment method is SCEP, everything is done in a single command.
R1/configure/crypto> ca enroll ms2003
Receive the router certificate from the CA server
December 2010

Advertisement

Table of Contents
loading

Table of Contents