10-21-2022 12:35 AM
Trying to generate a CSR on IOS-XR (NCS5001 platform version 6.5.3) ; the CSR gets generated correctly however when reviewing the parameters of the CSR it does not contain a COMMON name so out CA cannot sign the certificate.
Using the default key ring, trustpoint has been created with enrolment terminal configuration, the CA has been successfully imported (shows up under the show crypto ca certificates)
Anyone has an idea what might go wrong here ?
Snippet of the CSR:
"Certificate Request:
Data:
Version: 1 (0x0)
Subject: unstructuredName = cr01.ixbru.ipnexia.com, unstructuredAddress = 10.255.0.4
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (2048 bit)"
thanks for the feedback
Alexander
10-21-2022 10:05 AM
I'm not sure if its required for certificate creation or will even make a difference, but do you have a domain configured on the router?
Sam
10-23-2022 12:43 AM
Hi,
domain has been configured; I figured out that under the trustpoint I can configure the parameters as required however the CSR that is generated can not be signed by out CA. So a step closer but yet mot solved.
cheers
Alexander
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide