Creating a Trustpoint
Enter the
pki trustpoint
command to configure a PKI trustpoint and enter trustpoint configuration mode.
device(config)# pki trustpoint ruckus device(config-pki-trustpoint-ruckus)#
PKI functionality is configured and setup using the following commands.
device(config)# pki entity entity1 device(config-pki-entity-entity1)# common-name ruckus device(config-pki-entity-entity1)# org-unit-name FI device(config-pki-entity-entity1)# org-name RUCKUS device(config-pki-entity-entity1)# state-name KA device(config-pki-entity-entity1)# country-name IN device(config-pki-entity-entity1)# email-id user@ruckus.com device(config-pki-entity-entity1)# location BG
The
crypto key generate
command offers different methods of generating key-pairs. The following code sample
shows the command options available for key generation.
device# configure terminal device(config)# crypto key generate ? ec generate elliptical key pair for PKI rsa generate rsa key pair <cr> device(config)# crypto key generate rsa ? label input rsa label modulus generate rsa key size 2048 <cr>
The following example creates enrollment profile profile1 that is added to the configuration
for the trustpoint trust1. The trust1 configuration uses an eckeypair with the label
ec_2 that was previously generated with the
crypto key generate ec command.
device# configure terminal device(config)# pki profile-enrollment profile1 device(config-pki-profile-enrollment-profile1)# authentication-url http://FI-PKI02.englab.ruckus.com/CertSrv/mscep/mscep.dll device(config-pki-profile-enrollment-profile1)# enrollment-url http://FI-PKI02.englab.ruckus.com/CertSrv/mscep/mscep.dll device(config)#pki trustpoint trust1 device(config-pki-trustpoint-trust1)# enrollment retry-count 3 device(config-pki-trustpoint-trust1)# enrollment retry-period 2 device(config-pki-trustpoint-trust1)# enrollment profile profile1 device(config-pki-trustpoint-trust1)# pki-entity entity1 device(config-pki-trustpoint-trust1)# revocation-check crl device(config-pki-trustpoint-trust1)# crl-query http://FI-PKI02.englab.ruckus.com/CertEnroll/englab-FI-PKI02-CA.crl device(config-pki-trustpoint-trust1)# crl-update-time 1 device(config-pki-trustpoint-trust1)# eckeypair key-label ec_2 device(config-pki-trustpoint-trust1)# fingerprint 89:31:79:bd:50:55:ef:84:7f:0c:ae:9a:5c:12:d7:7b:fa:3b:d1:d8 device(config)#ikev2 auth-proposal a1 device(config-ike-auth-proposal-a1)# method remote ecdsa384 device(config-ike-auth-proposal-a1)# method local ecdsa384 device(config-ike-auth-proposal-a1)# pki-trustpoint trust1 sign device(config-ike-auth-proposal-a1)# pki-trustpoint trust1 verify
The following example configures the IKEv2 authentication proposal a1, which uses trustpoint trust1 to sign and verify certificates.
device(config)# ikev2 auth-proposal a1 device(config-ike-auth-proposal-a1)# method remote ecdsa384 device(config-ike-auth-proposal-a1)# method local ecdsa384 device(config-ike-auth-proposal-a1)# pki-trustpoint trust1 sign device(config-ike-auth-proposal-a1)# pki-trustpoint trust1 verify
The following authentication algorithms can also be configured apart from ecdsa384:
If pre-shared is selected, PKI functionality is not used. Instead, the pre-shared key is used to negotiate with peers, in which case, both endpoints must have the same pre-shared key configured.
The
pki authenticate
command is used to authenticate the trustpoint. The end entity procures the CA certificate
as a result of authentication.
device(config)# pki authenticate <trustpoint-name>
The
pki enroll command is used to enroll the trustpoint with the CA server. The end entity procures
its local certificate with a digital signature from the CA server as a result of enrollment.
device(config)# pki enroll <trustpoint-name>
The certificates for the end entity can be generated using PKI infrastructure or can be pre-generated and copied offline into the flash of the device.
The following commands are used to import stored certificates from the flash of the device.
device(config)# pki import trust1 pem url flash: <root-ca-file-name>.pem device(config)# pki import trust1 pem url flash: <end-entity-file-name>.pem device(config)# pki import key ec <key-label> pem url flash: <end-entity-key-file-name>.pem device(config)# pki import key rsa <key-label> pem url flash: <end-entity-key-file-name>.pem
The following commands are available to display information from the PKI database.
device# show pki certificates Display pki certificates counters Show PKI counters crls Show PKI Certification Revocation list if Any enrollment-profile Show PKI enrollment profile. entity Show PKI entity. key Show router public keys. logging-statistics Display pki logging statistics trustpoint Show PKI trustpoint information
The following
show pki certificates commands are used to display the certificate information associated with specific
trustpoints in the PKI database.
device# show pki certificates trustpoint <trustpoint-name> device# show pki certificates trustpoint <trustpoint-name> detail device# show pki certificates local trustpoint <trustpoint-name> device# show pki certificates local trustpoint <trustpoint-name> detail