05-12-2004 02:30 AM - edited 03-09-2019 07:21 AM
Hi
I am using digital certificates for IPSec tunnels between 2 routers using Microsoft CA server.
Can some one advise me how to configure auto enrolment feature with Cisco routers. As certificate enrolment request gets rejected by CA as the password/private key doesnt match with CA server.
thanks in advance.
05-12-2004 10:25 AM
hi,
U need to install the SCEP add-on from
Once this is done, U can configure the trust point as explained
Then check out http://cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00800948e3.shtml to configure IpSec using CA.
05-12-2004 11:35 AM
hi
I have succesfuly configured 2 routers using digital certififcates, I dont have any problem with that part of config. I am strugling to understand how in future router can renew a certificate from MS CA server without any manual interventation ( I know CA admin will have to issue certificate ) with auto enrol function. the sample config shown below also talks about password, now is this the password used while enroling for certificate ?
3640(config)#crypto ca trustpoint SJPKI
3640(ca-trustpoint)#auto-enroll
3640(ca-trustpoint)#password revokeme
What will happen when certificate on remote router expires, with auto enrol command, router will try to enrol for new certificate. now as per my understanding when you enrol you have to provide a password... I am confused how will it work.
regards
thanks
05-12-2004 12:53 PM
Hmm...I am not too sure about this either.
AFAIK, the password is only for certifcate revocation.
Also, in the MS CA Server, there is an "Auto-enroll" option , which is disabled by default. So perhaps you can try changing this and share your expirience.
Thanks,
~preetham
05-12-2004 02:26 PM
hi
where exactly in ca server, there is an auto-enrol option... i couldnt locate any where
thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide