cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
973
Views
0
Helpful
10
Replies

Enable to export CUBEs Self Signed Certificate

JaySchiller
Level 1
Level 1

Hello!
I want to setup a SIP TLS Trunk between 2 CUBES. I need to work with self signed certificates for now. 

So I created the certificate and all and now I want to export it on one CUBE and import it on the other. 

How can I do this? The command "crytpo pki export blablatrustpoint pem" does not exist. Only "crytpo pki export blablatrustpoint pkcs12" and that gives me this message: 

% Can not export a self-signed-trustpoint via pkcs#12.
% Please use 'pem'

Im on a vCUBE  C8000V (VXE) with version 17.6.5

Any help would be greatly appreciated. 

Thanks!  Jens

1 Accepted Solution

Accepted Solutions

No that is not it either. 

No such command "show cr*y*pto pki trustpoint <trustpoint-name> certificate" See screenshot. 

But I found it. "show cry*p*to pki certificates pem" thats it. 

View solution in original post

10 Replies 10

b.winter
VIP
VIP

crypto pki export <CUBE-TP> pem terminal

JaySchiller
Level 1
Level 1

Hi!  Like I said. That command does not exist!  I know that i mispronounced "crytpo".  That was on purpose. This website would not let me generate this post with the word "crytpo" in it. I believe it wants to see it in "Security" or something.

What does it say, when you enter "crypto pki export ?"
make a screenshot

How does your trustpoint config look like?

JaySchiller
Level 1
Level 1

Ok. Here are the screenshots

 

Please also post the trustpoint config.

Have you activated the security license?

license boot level securityk9 --> save config and reboot

JaySchiller
Level 1
Level 1

Trust Point Config Screenshot attached. 

There is no "license boot level securityk9" I also attached a screenshot that will show this. 

 

you already activated the network-essentials license?
please post the show version

M02@rt37
VIP
VIP

Hello @JaySchiller,

you can use the following command to export the self-signed certificate in PEM format and display it on the terminal:

show cr*y*pto pki trustpoint <trustpoint-name> certificate

Then you can copy and paste the output to a text editor and save it as a PEM file.

On the other CUBE, you can import the PEM file using the command:

cr*y*pto pki import <trustpoint-name> pem terminal
Then you can copy and paste the contents of the PEM file into the terminal and press Ctrl+D to complete the import process.

 

Best regards
.ı|ı.ı|ı. If This Helps, Please Rate .ı|ı.ı|ı.

No that is not it either. 

No such command "show cr*y*pto pki trustpoint <trustpoint-name> certificate" See screenshot. 

But I found it. "show cry*p*to pki certificates pem" thats it. 

JaySchiller
Level 1
Level 1

Yes I did.

 

 

 

kfw-f-vcubet01#show version
Cisco IOS XE Software, Version 17.06.05
Cisco IOS Software [Bengaluru], Virtual XE Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 17.6.5, RELEASE SOFTWARE (fc2)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2023 by Cisco Systems, Inc.
Compiled Wed 25-Jan-23 16:07 by mcpre


Cisco IOS-XE software, Copyright (c) 2005-2023 by cisco Systems, Inc.
All rights reserved.  Certain components of Cisco IOS-XE software are
licensed under the GNU General Public License ("GPL") Version 2.0.  The
software code licensed under GPL Version 2.0 is free software that comes
with ABSOLUTELY NO WARRANTY.  You can redistribute and/or modify such
GPL code under the terms of GPL Version 2.0.  For more details, see the
documentation or "License Notice" file accompanying the IOS-XE software,
or the applicable URL provided on the flyer accompanying the IOS-XE
software.


ROM: IOS-XE ROMMON

kfw-f-vcubet01 uptime is 2 hours, 25 minutes
Uptime for this control processor is 2 hours, 25 minutes
System returned to ROM by reload at 14:03:08 CEST Tue May 9 2023
System image file is "bootflash:packages.conf"
Last reload reason: Reload Command



This product contains crotpographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco crotpographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco crotpographic products may be found at:
http://www.cisco.com/wwl/export/crotpo/tool/stqrg.html

If you require further assistance please contact us by sending email to
export@cisco.com.

License Level: network-essentials
License Type: Perpetual
Next reload license Level: network-essentials

Addon License Level: dna-essentials
Addon License Type: Subscription
Next reload addon license Level: dna-essentials

The current throughput level is 250000 kbps


Smart Licensing Status: Registration Not Applicable/Not Applicable

cisco C8000V (VXE) processor (revision VXE) with 2026851K/3075K bytes of memory.
Processor board ID XXXXX
Router operating mode: Autonomous
3 Gigabit Ethernet interfaces
32768K bytes of non-volatile configuration memory.
3964640K bytes of physical memory.
11526144K bytes of virtual hard disk at bootflash:.

Configuration register is 0x2102