03-26-2024 02:00 AM
Hi,
I checked several guides how to deploy LSC on C9800 WLCs (https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9100-access-points/221127-configure-locally-significant-certificat.html / https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-management/215557-configure-scep-for-locally-significant-c.html), but the option to use a permanent password (not OTP) to authenticate towards the NDES server is never mentioned.
Within the trustpoint context, a password can be set, but according to the documentation this password if used to revocate the certificate.
Is there a chance to use a NDES server that has UseSinglePassword option enabled?
03-26-2024 03:12 AM
- On the NDES server edit the registry target (name) :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MSCEP\UseSinglePassword
which is set to 0 by default ; change the value to 1 instead ,
M.
03-26-2024 03:26 AM
But how need the WLC to be configured to send this password?
03-26-2024 05:18 AM
- In a first reaction I would presume that to be explained in the documentation (links) that you provided , if not clear ask further , = contact TAC for explanations and guidelines,
M.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide