Certificate Issuance To Routers Or Vpn Clients - Red Hat CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR Administrator's Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR:
Table of Contents

Advertisement

CEP Enrollment

Certificate Issuance to Routers or VPN Clients

In general, issuing a certificate to a router involves the following steps:
Note or print the certificate fingerprint information of the Certificate Manager CA
1.
signing certificate. You will be required to compare this with the fingerprint the router
will show on the screen.
To locate the fingerprint information:
a.
b.
c.
d.
e.
In your router documentation, locate the information specific to requesting certificates
2.
for routers. Check the signing algorithm, such as RSA or DSA, and key lengths, such as
512 and 1024, supported by the router. Based on that information, determine the
signing algorithm and the key length for the certificate you want to request.
Find out the password that enables you to access the router in privileged mode.
3.
In your router documentation, locate instructions for requesting certificates. You will
4.
be required to run the appropriate commands using this documentation.
Generate the Key Pair for the Router
5.
Run the appropriate commands for your router, and generate the key pair. You will be
required to provide the signing algorithm, such as RSA or DSA, and the key length,
such as 512 or 1024. The longer the key length, the more time the router takes to
generate the key pair.
Request the CA's Certificate
6.
In this part of the operation, you identify the CA to the router, thus enabling the router
to authenticate the CA from which it will request the certificate. You also verify
whether the router is talking to the right CA; you do this manually.
Here's what you should do:
a.
402
Red Hat Certificate System Administrator's Guide • September 2005
Go to the end-entity page hosted by the Certificate Manager.
Click the Retrieval tab.
List or search for the CA signing certificate.
Click Details.
Scroll down to the section that says "Certificate fingerprint."
Run the appropriate command to get the CA certificate.
The command will ask you to specify the following:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate system 7.1 - adminsistrator

Table of Contents