Chapter28 Public Key Infrastructure
Certificate Wizards
28-36
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
NTP not configuredThe router must have accurate time for certificate
enrollment to work. Identifying a Network Time Protocol server from which
your router can obtain accurate time provides a time source that is not
affected if the router needs to be rebooted. If your organization does not have
an NTP server, you may want to use a publicly available server, such as the
server described at the following URL:
http://www.eecis.udel.edu/~mills/ntp/clock2a.html
DNS not configuredSpecifying DNS servers helps ensure that the router is
able to contact the certificate server. DNS configuration is required to contact
the CA server and any other server related to certificate enrollment such as
OCSP servers or CRL repositories if those servers are entered as names and
not as IP addresses.
Domain and/or Hostname not configuredIt is recommended that you
configure a domain and hostname before beginning enrollment.
Simple Certificate Enrollment Protocol (SCEP)
Click this button if you can establish a direct connection between your route r and
a Certificate Authority (CA) server. You must have the servers enrollment URL
in order to do this. The wizard will do the following:
Gather information from you to configure a trustpoint and deliver it to the
router.
Initiate an enrollment with the CA server you specified in the trustpoint.
If the CA server is available, display the CA servers fingerprint for your
acceptance.
If you accept the CA server fingerprint , complete the enrollment.
Cut and Paste/Import from PC
Click this button if your router cannot establish a direct connection to the CA
server or if you want to generate an enrollment request and send it to the CA at
another time. After generation, the enrollment request can b e submitted to a CA
at another time. Cut-and-Paste enrollment requires you to invoke the Digital
Certificates wizard to generate a request, and then to reinvoke it when you have
obtained the certificates for the CA server and for the router.