cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1162
Views
0
Helpful
1
Replies

CA Server + Key Server(GetVPN)

henrry.huaman
Level 1
Level 1

Hi Guys,

Currently we are testing GetVPN and we need to integrate with CA Server.

Is possible to configure the CA Server and Key Server in the same device?
And, How many GMs is supported?

BR

Henrry

1 Reply 1

Chetankumar Phulpagare
Cisco Employee
Cisco Employee

Hi Henrry,

It is possible to configure GETVPN Key Server (KS) and CA Server on the same device. You can check below link for example:

https://supportforums.cisco.com/docs/DOC-13423

Generally it is recommeded to build a PKI server as Root-CA. Then each KS can register with the Root-CA and become Sub-CA.  Then the KS routers register with each Sub-CA.  Now the Root-CA can be taken off-line.  GM's only need to get a cert from one of the sub-CA servers.

Hope this helps.

Thanks,

Chetan

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: