Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


Enrolling and Installing Certificates

Nov 15,2009 by alperen

image

Enrolling and Installing Certificates

To use digital certificates for authentication, you must first enroll with a CA, and obtain and install the CA certificate on the VPN Concentrator. Then, you can enroll and install an identity certificate from the same CA. You can enroll and install digital certificates manually or automatically. The automatic method is a new feature that uses Simple Certificate Enrollment Protocol (SCEP), a secure messaging protocol that requires minimal user intervention to enroll and install certificates using only the VPN Concentrator Manager. SCEP was introduced in Chapter 11. SCEP is quicker than enrolling and installing digital certificates manually, but SCEP is available only if it meets the following two conditions:

  • The CA must support SCEP.

  • Enrolling must be done via the Internet.

If the CA doesn’t support SCEP or if digital certificates are enrolled by other means, such as by e-mail or floppy disk, then they must be processed using the manual method, which requires more steps.

In either case, whichever method is used to install a CA certificate must also be used to request identity or SSL certificates from that CA.

Certificate Task Summary

Regardless of whether SCEP or the manual method is used, the following tasks must be completed to obtain and install certificates:

  1. Request and install the required CA certificate(s).

  2. Create an enrollment request for one or more identity certificates.

  3. Request an identity certificate from the same CA that issued the CA certificate(s).

  4. Install the identity certificate on the VPN Concentrator.

  5. Enable CRL checking and caching.

  6. Enable certificates.


302 times read

Related news

» Simple Certificate Enrollment Protocol (SCEP)
by alperen posted on Nov 30,2009
» Using SCEP to Manage Certificates
by alperen posted on Nov 15,2009
» VPN Concentrator and Certificates
by alperen posted on Nov 15,2009
» LAN-to-LAN Networks with Digital Certificates
by alperen posted on Dec 31,2009
» CAs and Digital Certificates
by alperen posted on Sep 25,2009
Did you enjoy this article?
(total 0 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author