cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
277
Views
0
Helpful
2
Replies

NCS5001 CSR does not contain COMMON name

Alexander09
Level 1
Level 1

Trying to generate a CSR on IOS-XR (NCS5001 platform version 6.5.3) ; the CSR gets generated correctly however when reviewing the parameters of the CSR it does not contain a COMMON name so out CA cannot sign the certificate.

Using the default key ring, trustpoint has been created with enrolment terminal configuration, the CA has been successfully imported (shows up under the show crypto ca certificates)

Anyone has an idea what might go wrong here ?

Snippet of the CSR:

"Certificate Request:
Data:
Version: 1 (0x0)
Subject: unstructuredName = cr01.ixbru.ipnexia.com, unstructuredAddress = 10.255.0.4
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (2048 bit)"

thanks for the feedback

Alexander

--
Alexander Deca
2 Replies 2

smilstea
Cisco Employee
Cisco Employee

I'm not sure if its required for certificate creation or will even make a difference, but do you have a domain configured on the router?

 

Sam

 

Hi,

domain has been configured; I figured out that under the trustpoint I can configure the parameters as required however the CSR that is generated can not be signed by out CA. So a step closer but yet mot solved.

cheers

Alexander

--
Alexander Deca