Cisco CP-7911G-CH1 System Administrator Manual page 191

Unified sccp and sip srst
Table of Contents

Advertisement

Configuring Secure SRST for SCCP and SIP
DETAILED STEPS
Command or Action
Step 1
crypto pki server cs-label
Example:
Router (config)# crypto pki server srstcaserver
Step 2
shutdown
Example:
Router (cs-server)# shutdown
Step 3
no grant auto
Example:
Router (cs-server)# no grant auto
Step 4
no shutdown
Example:
Router (cs-server)# no shutdown
What to Do Next
For manual enrollment instructions, see the
feature.
Verifying Certificate Enrollment
If you used the Cisco IOS certificate server as your CA, use the show running-config command to verify
certificate enrollment or the show crypto pki server command to verify the status of the CA server.
SUMMARY STEPS
1.
2.
OL-13143-04
show running-config
show crypto pki server
Purpose
Enables the certificate server and enters certificate server
configuration mode.
Note
If you manually generated an RSA key pair, the
cs-label argument must match the name of the key
pair.
Disables the Cisco IOS certificate server.
Disables automatic certificates to be issued to any
requestor.
This command was for use during enrollment only and
thus needs to be removed in this task.
Enables the Cisco IOS certificate server.
You should issue this command only after you have
completely configured your certificate server.
Manual Certificate Enrollment (TFTP and Cut-and-Paste)
Cisco Unified SCCP and SIP SRST System Administrator Guide
How to Configure Secure Unified SRST
191

Advertisement

Table of Contents
loading

Table of Contents