cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
836
Views
0
Helpful
3
Replies

Deploy LSC via 9800 using NDES with UseSinglePassword=1 enabled

Tobias Heisele
Level 3
Level 3

Hi,

I checked several guides how to deploy LSC on C9800 WLCs (https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9100-access-points/221127-configure-locally-significant-certificat.html / https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-management/215557-configure-scep-for-locally-significant-c.html), but the option to use a permanent password (not OTP) to authenticate towards the NDES server is never mentioned.
Within the trustpoint context, a password can be set, but according to the documentation this password if used to revocate the certificate.
Is there a chance to use a NDES server that has UseSinglePassword option enabled?

3 Replies 3

Mark Elsen
Hall of Fame
Hall of Fame

 

                      - On  the NDES server edit the registry target (name) :
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MSCEP\UseSinglePassword
                                       which is set to 0  by  default ;  change the value to 1 instead , 

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

But how need the WLC to be configured to send this password?

 

 - In a first reaction I would presume that to be explained in the documentation (links)  that you provided , if not clear ask further , = contact TAC for explanations and guidelines, 

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)
Review Cisco Networking for a $25 gift card