Cisco CRS-1 - Carrier Routing System Router Configuration Manual page 68

Ios xr system security configuration guide
Hide thumbs Also See for CRS-1 - Carrier Routing System Router:
Table of Contents

Advertisement

Contents
Contents
Prerequisites for Implementing Certification Authority
The following prerequisites are required to implement CA interoperability:
Restrictions for Implementing Certification Authority
Cisco IOS XR software does not support CA server public keys greater than 2048 bits.
Information About Implementing Certification Authority
To implement CA, you need to understand the following concepts:
Supported Standards for Certification Authority Interoperability
Cisco supports the following standards:
Cisco IOS XR System Security Configuration Guide for the Cisco CRS-1 Router
SC-62
Prerequisites for Implementing Certification Authority, page SC-62
Restrictions for Implementing Certification Authority, page SC-62
Information About Implementing Certification Authority, page SC-62
How to Implement CA Interoperability, page SC-66
Configuration Examples for Implementing Certification Authority Interoperability, page SC-75
Additional References, page SC-77
You must be in a user group associated with a task group that includes the proper task IDs. The
command reference guides include the task IDs required for each command.
If you suspect user group assignment is preventing you from using a command, contact your AAA
administrator for assistance.
You must install and activate the Package Installation Envelope (PIE) for the security software.
For detailed information about optional PIE installation, refer to Cisco IOS XR System Management
Guide.
You need to have a CA available to your network before you configure this interoperability feature.
The CA must support Cisco Systems PKI protocol, the simple certificate enrollment protocol
(SCEP) (formerly called certificate enrollment protocol [CEP]).
Supported Standards for Certification Authority Interoperability, page SC-62
Certification Authorities, page SC-63
IPSec—IP Security Protocol. IPSec is a framework of open standards that provides data
confidentiality, data integrity, and data authentication between participating peers. IPSec provides
these security services at the IP layer; it uses Internet Key Exchange (IKE) to handle negotiation of
Implementing Certification Authority Interoperability on Cisco IOS XR Software
OL-20382-01

Advertisement

Table of Contents
loading

Table of Contents