Chapter19 Public Key Infrastructure
Certificate Wizards
19-2
Cisco Router and Security Device Manager 2.5 User’s Guide
OL-4015-12

Simple Certificate Enrollment Protocol (SCEP)

Click this button if you can establish a direct connection between your route r and
a Certificate Authority (CA) server. You must have the server’s enrollment URL
in order to do this. The wizard will do the following:
Gather information from you to configure a trustpoint and deliver it to the
router.
Initiate an enrollment with the CA server you specified in the trustpoint.
If the CA server is available, display the CA server’s fingerprint for your
acceptance.
If you accept the CA server fingerprint , complete the enrollment.

Cut and Paste/Import from PC

Click this button if your router cannot establish a direct connection to the CA
server or if you want to generate an enrollment request and send it to the CA at
another time. After generation, the enrollment request can b e submitted to a CA
at another time. Cut-and-Paste enrollment requires you to invoke the Digital
Certificates wizard to generate a request, and then to reinvoke it when you have
obtained the certificates for the CA server and for the router.
Note Cisco SDM supports only base-64-encoded PKCS#10-type cut and paste
enrollment. Cisco SDM does not support importing PEM and PKCS#12 type
certificate enrollments.

Launch the selected task button

Click to begin the wizard for the type of enrollment that you selected. If Cisco
SDM has detected a required task that must be performed before enrollment can
begin, this button is disabled. Once the task is completed, the button is enabled.
Welcome to the SCEP Wizard
This screen indicates that you are using the SCEP wizard. If you do not want to
use the Simple Certificate Enrollment Process, click Cancel to leave this wizard.