Scep Setup - Cisco 8811 Administration Manual

8800 series for cisco unified communications manager
Hide thumbs Also See for 8811:
Table of Contents

Advertisement

Supported Security Features

SCEP Setup

Simple Certificate Enrollment Protocol (SCEP) is the standard for automatically provisioning and renewing
certificates. It avoids manual installation of certificates on your phones.
Configure the SCEP Product Specific Configuration Parameters
You must configure the following SCEP parameters on your phone web page
• RA IP address
• SHA-1 or SHA-256 fingerprint of the root CA certificate for the SCEP server
The Cisco IOS Registration Authority (RA) serves as a proxy to the SCEP server. The SCEP client on the
phone use the parameters that are downloaded from Cisco Unified Communication Manager. After you
configure the parameters, the phone sends a SCEP getcs request to the RA and the root CA certificate is
validated using the defined fingerprint.
Procedure
Step 1
From the Cisco Unified Communications Manager Administration, select Device > Phone.
Step 2
Locate the phone.
Step 3
Scroll to the Product Specific Configuration Layout area.
Step 4
Check the WLAN SCEP Server check box to activate the SCEP parameter.
Step 5
Check the WLAN Root CA Fingerprint (SHA256 or SHA1) check box to activate the SCEP QED parameter.
Simple Certificate Enrollment Protocol Server Support
If you are using a Simple Certificate Enrollment Protocol (SCEP) server, the server can automatically maintain
your user and server certificates. On the SCEP server, configure the SCEP Registration Agent (RA) to:
• Act as a PKI trust point
• Act as a PKI RA
• Perform device authentication using a RADIUS server
For more information, see your SCEP server documentation.
802.1X Authentication
The Cisco IP Phones support 802.1X Authentication.
Cisco IP Phones and Cisco Catalyst switches traditionally use Cisco Discovery Protocol (CDP) to identify
each other and determine parameters such as VLAN allocation and inline power requirements. CDP does not
identify locally attached workstations. Cisco IP Phones provide an EAPOL pass-through mechanism. This
mechanism allows a workstation attached to the Cisco IP Phone to pass EAPOL messages to the 802.1X
authenticator at the LAN switch. The pass-through mechanism ensures that the IP phone does not act as the
LAN switch to authenticate a data endpoint before accessing the network.
Cisco IP Phones also provide a proxy EAPOL Logoff mechanism. In the event that the locally attached PC
disconnects from the IP phone, the LAN switch does not see the physical link fail, because the link between
Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager
108

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

884588518851nr886188658865nr ... Show all

Table of Contents