Cisco CP-7911G-CH1 System Administrator Manual page 197

Unified sccp and sip srst
Table of Contents

Advertisement

Configuring Secure SRST for SCCP and SIP
Copy all of the contents that appear between "-----BEGIN CERTIFICATE-----" and "-----END
Step 8
CERTIFICATE-----" to a location where you can retrieve it later.
Step 9
Repeat Steps 5 to 8 for CiscoManufactureCA, CiscoRootCA2048, and CAPF.
Cisco Unified Communications Manager 6.0 and Later Versions
From Cisco Unified Communications Operating System Administration, download all certificates listed
under CAPF-trust, including Cisco_Manufacturing_CA, Cisco_Root_CA_2048, CAP-RTP-001,
CAP-RTP-002, CAPF, and CAPF-xxx. Also download any CAPF-xxx certificates that are listed under
CallManager-trust and not under CAPF-trust.
For instructions on downloading certificates, see the "Security" chapter in the appropriate version of
Cisco Unified Communications Operating System Administration Guide.
Authenticating the Imported Certificates on the Cisco Unified SRST Router
To authenticate certificates on the Cisco Unified SRST router, perform these steps.
Restrictions
HTTP automatic enrollment from Cisco Unified Communications Manager through a virtual web server
is not supported.
SUMMARY STEPS
1.
2.
3.
4.
5.
DETAILED STEPS
Command or Action
Step 1
crypto pki trustpoint name
Example:
Router (config)# crypto pki trustpoint CAPF
Step 2
revocation-check none
Example:
Router(ca-trustpoint)# revocation-check none
Step 3
enrollment terminal
Example:
Router(ca-trustpoint)# enrollment terminal
OL-13143-04
crypto pki trustpoint name
revocation-check none
enrollment terminal
exit
crypto pki authenticate name
Purpose
Declares the CA that your router should use and enters
ca-trustpoint configuration mode.
name: Enter the name of each certificate individually
(for example, CAPF, CiscoCA, CiscoManufactureCA,
and CiscoRootCA2048).
Checks the revocation status of a certificate using the
selected method.
Using the none keyword is mandatory for this task.
The keyword none means that a revocation check is
not performed and the certificate is always accepted.
Specifies manual cut-and-paste certificate enrollment.
Cisco Unified SCCP and SIP SRST System Administrator Guide
How to Configure Secure Unified SRST
197

Advertisement

Table of Contents
loading

Table of Contents