<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Better Understanding of the Device Certificate Process in Controllers</title>
    <link>https://community.cisco.com/t5/controllers/better-understanding-of-the-device-certificate-process/m-p/3499783#M2772</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Claudia,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;there are two ways a certificate will be created on a switch (not access point).&lt;/P&gt;&lt;P&gt;1) If you click on device certificate, then APIC-EM will create and download a certificate to the device.&amp;nbsp; This&amp;nbsp; certificate can be used by SSH etc.&lt;/P&gt;&lt;P&gt;2) If you have "ip https server" in the config, then the device will create a self signed certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#1 is probably preferable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you wanted to add/create other certificates, you would need to do this outside of PnP, possibly using an EEM script etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this answer your question?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Adam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 19 Dec 2016 03:41:56 GMT</pubDate>
    <dc:creator>aradford</dc:creator>
    <dc:date>2016-12-19T03:41:56Z</dc:date>
    <item>
      <title>Better Understanding of the Device Certificate Process</title>
      <link>https://community.cisco.com/t5/controllers/better-understanding-of-the-device-certificate-process/m-p/3499781#M2770</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Id like to get a better understanding of the certificate process in APIC-EM.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What happens if we say Device Certificate = False?&amp;nbsp; the PNP communication takes place in clear text?&amp;nbsp; If&amp;nbsp; i then need a cert to establish ssh access, how does that happen as that is typically an interactive process.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we do say "True" we now have a PNP certificate on the device.&amp;nbsp; What if the APIC-EM provisioning step is a one time thing.&amp;nbsp; Should we leave the cert there.&amp;nbsp; What if we want to create another certificate for general ssh login access different from the PNP cert?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suspect that all these questions are a clear indication I don't have a good grasp of this process!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any info or pointers!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Claudia&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" style="width: 126px;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD height="20" width="126"&gt;Device Certificate*&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD align="center" height="20"&gt;False&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2019 12:34:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/better-understanding-of-the-device-certificate-process/m-p/3499781#M2770</guid>
      <dc:creator>Claudia de Luna</dc:creator>
      <dc:date>2019-03-01T12:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: Better Understanding of the Device Certificate Process</title>
      <link>https://community.cisco.com/t5/controllers/better-understanding-of-the-device-certificate-process/m-p/3499782#M2771</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Plug-and-Play/software/guide/pnp_apic_em_config_guide/pnp_apic_em_config_guide_chapter_01.html?referring_site=RE&amp;amp;pos=1&amp;amp;page=http://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Plug-and-Play/solution/guide/pnp-solution-guide.html" title="http://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Plug-and-Play/software/guide/pnp_apic_em_config_guide/pnp_apic_em_config_guide_chapter_01.html?referring_site=RE&amp;amp;pos=1&amp;amp;page=http://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Plug-and-Play/solution/guide/pnp-solution-guide.html"&gt;Configuration Guide for Cisco Network Plug and Play on Cisco APIC-EM - Configuring Cisco Network Plug and Play [Cisco …&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #525252; font-family: arial, helvetica, 'Helvetica Neue', HelveticaNeue, 'Lucida Grande', sans-serif; font-size: 14px;"&gt;Check the &lt;/SPAN&gt;&lt;STRONG style="font-size: 14px; font-family: arial, helvetica, 'Helvetica Neue', HelveticaNeue, 'Lucida Grande', sans-serif; color: #525252;"&gt;Device Certificate&lt;/STRONG&gt;&lt;SPAN style="color: #525252; font-family: arial, helvetica, 'Helvetica Neue', HelveticaNeue, 'Lucida Grande', sans-serif; font-size: 14px;"&gt; check box to apply the device certificate on the device. Cisco Network Plug and Play automatically generates and deploys the PKCS12 device ID certificate. Device Certificate is not supported on access point devices.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Dec 2016 21:09:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/better-understanding-of-the-device-certificate-process/m-p/3499782#M2771</guid>
      <dc:creator>sairasan</dc:creator>
      <dc:date>2016-12-15T21:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: Better Understanding of the Device Certificate Process</title>
      <link>https://community.cisco.com/t5/controllers/better-understanding-of-the-device-certificate-process/m-p/3499783#M2772</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Claudia,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;there are two ways a certificate will be created on a switch (not access point).&lt;/P&gt;&lt;P&gt;1) If you click on device certificate, then APIC-EM will create and download a certificate to the device.&amp;nbsp; This&amp;nbsp; certificate can be used by SSH etc.&lt;/P&gt;&lt;P&gt;2) If you have "ip https server" in the config, then the device will create a self signed certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#1 is probably preferable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you wanted to add/create other certificates, you would need to do this outside of PnP, possibly using an EEM script etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this answer your question?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Adam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Dec 2016 03:41:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/better-understanding-of-the-device-certificate-process/m-p/3499783#M2772</guid>
      <dc:creator>aradford</dc:creator>
      <dc:date>2016-12-19T03:41:56Z</dc:date>
    </item>
  </channel>
</rss>

