Cisco 3002 - VPN Hardware Client Spezifikationen Seite 166

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 318
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 165
12-18
VPN 3002 Hardware Client Reference, Release 4.0
OL-3813-01
Chapter 12 Administration
Managing Certificates with SCEP
The manual method involves more steps. You can do some of the steps using the Manager. Other
steps require that you exchange information with the CA directly. You deliver your enrollment
request and receive the certificate from the CA via the Internet, email, or a floppy disk.
Note If you install a CA certificate using the manual method, you must also use the manual method to request
identity or SSL certificates from that CA. Conversely, to request identity and SSL certificates using
SCEP, you must first use SCEP to obtain the CA certificate.
Tasks Summary
Whether you use SCEP or the manual method, you perform the following tasks to obtain and install
certificates:
1. Obtain and install one or more CA certificate(s).
2. Create an enrollment request for an identity certificates.
3. Request an identity certificate from the same CA that issued the CA certificate(s).
4. Install the identity certificate on the VPN Concentrator.
5. Enable certificates.
About the Documentation
The print version of this guide provides step-by-step examples of configuring digital certificates using
SCEP and manually, beginning with the next section, Managing Certificates with SCEP.
The online Help and the print version both provide detailed information on the parameters for each of
the Manager screens that you use to configure digital certificates.
Managing Certificates with SCEP
The following sections provide step-by-step instructions for using SCEP to enroll and install digital
certificates.
Obtaining and Installing CA Certificates Automatically Using SCEP
To use SCEP to enroll for identity or SSL certificates, you must also use SCEP to obtain the associated
CA certificate. The Manager does not let you enroll for a certificate from a CA unless that CA certificate
was installed using SCEP. A certificate that is obtained via SCEP and therefore capable of issuing other
SCEP certificates, is called SCEP-enabled.
Tip To obtain CA certificates using SCEP, you need to know the URL of your CA. Find out your CAs SCEP
URL before beginning the following steps.
Step 1 Using the VPN Concentrator Manager, display the Administration | Certificate Management screen. (See
Figure 12-19.)
Seitenansicht 165
1 2 ... 161 162 163 164 165 166 167 168 169 170 171 ... 317 318

Kommentare zu diesen Handbüchern

Keine Kommentare