Configuring PKI

You can create PKI entities for use in certificate authentication. To participate in certificate authentication with a Certificate Authority (CA), PKI entities must be enrolled. Entities can be enrolled through an automatic enrollment process, which allows them to send a certificate signing request (CSR) and to receive the required X.509 certificates from the CA in response. Entities can also be enrolled manually as described in the section "PKI manual import." The following procedure explains how to configure automatic enrollment.

Configuring PKI involves the following tasks:

  • Generate a cryptographic key using either the ec (elliptical key pair) or the rsa key pair option for PKI.
  • Create a PKI entity.
  • Configure the PKI profile.
  • Configure the PKI trustpoint.
  • Authenticate the PKI.
  • Enroll the PKI.

Perform the following steps to complete these tasks.

  1. Create a cryptographic key as shown in the following example.
    The first example generates a key pair using the rsa option for the PKI. The second example generates an elliptical key pair for the PKI.
    device# configure terminal
    device(config)# crypto key generate rsa label < name >
    device# configure terminal
    device(config)# crypto key generate ec label < name >
  2. Enter PKI entity configure submode to configure end user parameters.
    Note: PKI entity configuration is used for auto-enrollment only.
    The following example enters configuration submode for the PKI entity named entity1.
    device (config)# pki entity entity1
    device(config-pki-entity-entity1)#
    
  3. Configure PKI entity details, including common name, country name, state name, and organization name. Country names use a two-letter abbreviation.
    Note: It is recommended that you use quotes around text strings. Quotes are required when a name includes a space.
    The first example below provides command syntax for entering PKI entity details.
    The second example configures realistic parameters for entity1.
    device(config-pki-entity-entity1)# common-name < name >
    device(config-pki-entity-entity1)# country-name < country-name >
    device(config-pki-entity-entity1)# state-name < state-name >
    device(config-pki-entity-entity1)# org-unit-name < unit-name >
    device(config-pki-entity-entity1)# org-name < org-name >
    device(config-pki-entity-entity1)# email-id < email-address >
    device(config-pki-entity-entity1)# location < location-name >
    device(config-pki-entity-entity1)# 
    device(config-pki-entity-entity1)# exit
    
    device(config-pki-entity-entity1)# common-name "tester1"
    device(config-pki-entity-entity1)# country-name "IN"
    device(config-pki-entity-entity1)# state-name "KA"
    device(config-pki-entity-entity1)# org-unit-name "FI"
    device(config-pki-entity-entity1)# org-name "Ruckus"
    device(config-pki-entity-entity1)# email-id "user@ruckus.com"
    device(config-pki-entity-entity1)# location "BG"
    device(config-pki-entity-entity1)# 
    device(config-pki-entity-entity1)# exit
    
  4. Configure the PKI enrollment profile for use later in the enrollment process, including the following items:
    • Profile name
    • An authentication URL for the CA server where authentication requests are sent (for automatic enrollment only)
    • An enrollment URL for the CA server where enrollment requests are sent (for automatic enrollment only)
    • The challenge password obtained from the CA
    The following example provides profile enrollment syntax.
    device(config)# pki profile-enrollment < profile-name >
    device(config-pki-profile-enrollment-profile1)# authentication-url < URL >
    device(config-pki-profile-enrollment-profile1)# authentication-command < command >
    device(config-pki-profile-enrollment-profile1)# enrollment-url < URL >
    device(config-pki-profile-enrollment-profile1)# password < password >
    
    The following example configures the PKI enrollment profile named profile1.
    device(config)# pki profile-enrollment profile1
    device(config-pki-profile-enrollment-profile1)# authentication-url http://WIN-N6C3R0LUDAJ.englab.ruckus.com/CertSrv/mscep/mscep.dll
    device(config-pki-profile-enrollment-profile1)# authentication-command WIN-N6C3R0LUDAJ.englab.ruckus.com_englab-WIN-N6C3R0LUDAJ-CA-15
    device(config-pki-profile-enrollment-profile1)# enrollment-url http://WIN-N6C3R0LUDAJ.englab.ruckus.com/CertSrv/mscep/mscep.dll
    device(config-pki-profile-enrollment-profile1)# password DB6E1F091AEF0244
    device(config-pki-profile-enrollment-profile1)# exit
    
    
  5. Configure the trustpoint name and details, including the following items:
    • The enrollment option (automatic)
    • Enrollment retry-period (1 through 60 minutes)
    • Name of enrollment profile to used in the enrollment process
    • Name of the pre-configured PKI entity to be enrolled
    • Key pair type and label (for key generated previously using crypto commands)
    • Digital fingerprint for rootca (obtained from the rootca certificate)
    • OCSP transport protocol (HTTP) and method (post)
    The following example provides PKI trustpoint command syntax.
    device(config)# pki trustpoint < trustpoint-name >
    device(config-pki-trustpoint-trust1)# auto-enroll
    device(config-pki-trustpoint-trust1)# enrollment retry-period < number >
    device(config-pki-trustpoint-trust1)# enrollment profile < profile-name >
    device(config-pki-trustpoint-trust1)# pki-entity < entity-name >
    device(config-pki-trustpoint-trust1)# { eckeypair | rsakeypair } key-label < label >
    device(config-pki-trustpoint-trust1)# fingerprint < fingerprint-value >
    device(config-pki-trustpoint-trust1)# ocsp http post
    device(config-pki-trustpoint-trust1)# exit
    
    The following example configures the PKI trustpoint named trust1.
    device(config)# pki trustpoint trust1
    device(config-pki-trustpoint-trust1)# auto-enroll
    device(config-pki-trustpoint-trust1)# enrollment retry-period 2
    device(config-pki-trustpoint-trust1)# enrollment profile profile1
    device(config-pki-trustpoint-trust1)# pki-entity entity1
    device(config-pki-trustpoint-trust1)# eckeypair key-label eckeyAuto
    device(config-pki-trustpoint-trust1)# fingerprint 36:0c:92:6e:df:b2:72:eb:59:e8:63:73:2a:98:a8:91:cb:50:94:d9
    device(config-pki-trustpoint-trust1)# ocsp http post
    device(config-pki-trustpoint-trust1)# exit
    
  6. Authenticate the CA (trust1 in this example) to the FastIron device by obtaining the self-signed certificate from the CA.

    The following example authenticates previously configured trustpoint trust1.

    device(config)# pki authenticate trust1
    
  7. Once the trustpoint has been authenticated, enroll the FastIron device with the PKI trustpoint to obtain a local certificate signed by the CA server. The pki enroll command sends a CSR request to the CA with the configured keypair and entity values. The CA server signs it and sends back the client certificate for the given trustpoint.
    The following example enrolls the PKI trustpoint trust1.
    device(config)# pki enroll trust1
    
    The FastIron device, once enrolled, requests certificates from the CA for each of its key pairs. The CA sends the response in the form of a local certificate.

The following example creates a PKI entity, configures a PKI enrollment profile, and specifies automatic enrollment as the enrollment method. It then configures an enrollment profile. Next, it creates a trustpoint containing the previously configured enrollment profile and PKI entity. Finally, it authenticates and enrolls the trustpoint.

device# configure terminal
device (config)# pki entity entity1
device(config-pki-entity-entity1)# common-name "tester1"
device(config-pki-entity-entity1)# country-name "IN"
device(config-pki-entity-entity1)# state-name "KA"
device(config-pki-entity-entity1)# org-unit-name "FI"
device(config-pki-entity-entity1)# org-name "Ruckus"
device(config-pki-entity-entity1)# email-id "user@ruckus.com"
device(config-pki-entity-entity1)# location "BG"
device(config-pki-entity-entity1)# exit
device(config)# pki profile-enrollment profile1
device(config-pki-profile-enrollment-profile1)# authentication-url http://WIN-N6C3R0LUDAJ.englab.ruckus.com/CertSrv/mscep/mscep.dll
device(config-pki-profile-enrollment-profile1)# authentication-command WIN-N6C3R0LUDAJ.englab.ruckus.com_englab-WIN-N6C3R0LUDAJ-CA-15
device(config-pki-profile-enrollment-profile1)# enrollment-url http://WIN-N6C3R0LUDAJ.englab.ruckus.com/CertSrv/mscep/mscep.dll
device(config-pki-profile-enrollment-profile1)# password DB6E1F091AEF0244
device(config-pki-profile-enrollment-profile1)# exit
device(config)# pki trustpoint trust1
device(config-pki-trustpoint-trust1)# auto-enroll
device(config-pki-trustpoint-trust1)# enrollment retry-period 2
device(config-pki-trustpoint-trust1)# enrollment profile profile1
device(config-pki-trustpoint-trust1)# pki-entity entity1
device(config-pki-trustpoint-trust1)# eckeypair key-label eckeyAuto
device(config-pki-trustpoint-trust1)# fingerprint 36:0c:92:6e:df:b2:72:eb:59:e8:63:73:2a:98:a8:91:cb:50:94:d9
device(config-pki-trustpoint-trust1)# ocsp http post
device(config-pki-trustpoint-trust1)# exit
device(config)# pki authenticate trust1
device(config)# pki enroll trust1