06-06-2014 01:18 PM
Hi,
I am trying to configure PKI on our new ASR1002-X routers. They are running advipservices IOS-XE 3.10s.
When trying to configure the PKI CA the crypto pki server command is not there. Also the sctp configuration option under ipc / associaction1 seem to be missing.
VPN-ASR1002-1#sh ver
Cisco IOS XE Software, Version 03.10.02.S - Extended Support Release
Cisco IOS Software, ASR1000 Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 15.3(3)S2, RELEASE SOFTWARE (fc3)
VPN-ASR1002-2(config)#crypto pki ?
authenticate Get the CA certificate
certificate Actions on certificates
crl Actions on certificate revocation lists
enroll Request a certificate from a CA
export Export certificate or PKCS12 file
import Import certificate or PKCS12 file
profile Define a certificate profile
token Configure cryptographic token
trustpoint Define a CA trustpoint
trustpool Define CA trustpool
I am missing something here?
Regards
Thomas
06-07-2014 12:28 AM
Thomas,
This code was never ported to IOS XE.
https://tools.cisco.com/bugsearch/bug/CSCul30163/?reffering_site=dumpcr
M.
08-04-2014 03:58 AM
Hi Marcin
I notice the bug has a fixed release of 15.5(0.13)S.
Can you confirm?
Our new hubs are 1002-x and we were planning to use the IOS PKI Server rather than mess with the Microsoft one.
Would prefer not to have to deploy a pair of ISR's for this.
08-11-2014 01:11 AM
The pre-commits are done (dated early July) and it looks like the code exists, but I do not see commits done. Or it could be a problem with the tools.
Possibly waiting for commit window, best to check with SE about the roadmap.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide