Configuring PKI
You can create PKI entities for use in certificate authentication. To participate in certificate authentication with a Certificate Authority (CA), PKI entities must be enrolled. Entities can be enrolled through an automatic enrollment process, which allows them to send a certificate signing request (CSR) and to receive the required X.509 certificates from the CA in response. Entities can also be enrolled manually as described in the section "PKI manual import." The following procedure explains how to configure automatic enrollment.
Configuring PKI involves the following tasks:
- Generate a cryptographic key using either the ec (elliptical key pair) or the rsa key pair option for PKI.
- Create a PKI entity.
- Configure the PKI profile.
- Configure the PKI trustpoint.
- Authenticate the PKI.
- Enroll the PKI.
Perform the following steps to complete these tasks.
- Create a cryptographic key as shown in the following example.
The first example generates a key pair using the rsa option for the PKI. The second example generates an elliptical key pair for the PKI.
- Enter PKI entity configure submode to configure end user parameters.
Note: PKI entity configuration is used for auto-enrollment only.The following example enters configuration submode for the PKI entity named entity1.
- Configure PKI entity details, including common name, country name, state name, and
organization name. Country names use a two-letter abbreviation.
Note: It is recommended that you use quotes around text strings. Quotes are required when a name includes a space.The first example below provides command syntax for entering PKI entity details.The second example configures realistic parameters for entity1.
device(config-pki-entity-entity1)# common-name < name > device(config-pki-entity-entity1)# country-name < country-name > device(config-pki-entity-entity1)# state-name < state-name > device(config-pki-entity-entity1)# org-unit-name < unit-name > device(config-pki-entity-entity1)# org-name < org-name > device(config-pki-entity-entity1)# email-id < email-address > device(config-pki-entity-entity1)# location < location-name > device(config-pki-entity-entity1)# device(config-pki-entity-entity1)# exit
device(config-pki-entity-entity1)# common-name "tester1" device(config-pki-entity-entity1)# country-name "IN" device(config-pki-entity-entity1)# state-name "KA" device(config-pki-entity-entity1)# org-unit-name "FI" device(config-pki-entity-entity1)# org-name "Ruckus" device(config-pki-entity-entity1)# email-id "user@ruckus.com" device(config-pki-entity-entity1)# location "BG" device(config-pki-entity-entity1)# device(config-pki-entity-entity1)# exit
- Configure the PKI enrollment profile for use later in the enrollment process, including
the following items:
The following example provides profile enrollment syntax.
device(config)# pki profile-enrollment < profile-name > device(config-pki-profile-enrollment-profile1)# authentication-url < URL > device(config-pki-profile-enrollment-profile1)# authentication-command < command > device(config-pki-profile-enrollment-profile1)# enrollment-url < URL > device(config-pki-profile-enrollment-profile1)# password < password >
The following example configures the PKI enrollment profile named profile1.device(config)# pki profile-enrollment profile1 device(config-pki-profile-enrollment-profile1)# authentication-url http://WIN-N6C3R0LUDAJ.englab.ruckus.com/CertSrv/mscep/mscep.dll device(config-pki-profile-enrollment-profile1)# authentication-command WIN-N6C3R0LUDAJ.englab.ruckus.com_englab-WIN-N6C3R0LUDAJ-CA-15 device(config-pki-profile-enrollment-profile1)# enrollment-url http://WIN-N6C3R0LUDAJ.englab.ruckus.com/CertSrv/mscep/mscep.dll device(config-pki-profile-enrollment-profile1)# password DB6E1F091AEF0244 device(config-pki-profile-enrollment-profile1)# exit
- Configure the trustpoint name and details, including the following items:
- The enrollment option (automatic)
- Enrollment retry-period (1 through 60 minutes)
- Name of enrollment profile to used in the enrollment process
- Name of the pre-configured PKI entity to be enrolled
- Key pair type and label (for key generated previously using crypto commands)
- Digital fingerprint for rootca (obtained from the rootca certificate)
- OCSP transport protocol (HTTP) and method (post)
The following example provides PKI trustpoint command syntax.device(config)# pki trustpoint < trustpoint-name > device(config-pki-trustpoint-trust1)# auto-enroll device(config-pki-trustpoint-trust1)# enrollment retry-period < number > device(config-pki-trustpoint-trust1)# enrollment profile < profile-name > device(config-pki-trustpoint-trust1)# pki-entity < entity-name > device(config-pki-trustpoint-trust1)# { eckeypair | rsakeypair } key-label < label > device(config-pki-trustpoint-trust1)# fingerprint < fingerprint-value > device(config-pki-trustpoint-trust1)# ocsp http post device(config-pki-trustpoint-trust1)# exitThe following example configures the PKI trustpoint named trust1.device(config)# pki trustpoint trust1 device(config-pki-trustpoint-trust1)# auto-enroll device(config-pki-trustpoint-trust1)# enrollment retry-period 2 device(config-pki-trustpoint-trust1)# enrollment profile profile1 device(config-pki-trustpoint-trust1)# pki-entity entity1 device(config-pki-trustpoint-trust1)# eckeypair key-label eckeyAuto device(config-pki-trustpoint-trust1)# fingerprint 36:0c:92:6e:df:b2:72:eb:59:e8:63:73:2a:98:a8:91:cb:50:94:d9 device(config-pki-trustpoint-trust1)# ocsp http post device(config-pki-trustpoint-trust1)# exit
- Authenticate the CA (trust1 in this example) to the FastIron device by obtaining the self-signed certificate from the CA.
- Once the trustpoint has been authenticated, enroll the FastIron device with the PKI
trustpoint to obtain a local certificate signed by the CA server. The
pki enrollcommand sends a CSR request to the CA with the configured keypair and entity values. The CA server signs it and sends back the client certificate for the given trustpoint.The following example enrolls the PKI trustpoint trust1.The FastIron device, once enrolled, requests certificates from the CA for each of its key pairs. The CA sends the response in the form of a local certificate.
The following example creates a PKI entity, configures a PKI enrollment profile, and specifies automatic enrollment as the enrollment method. It then configures an enrollment profile. Next, it creates a trustpoint containing the previously configured enrollment profile and PKI entity. Finally, it authenticates and enrolls the trustpoint.
device# configure terminal device (config)# pki entity entity1 device(config-pki-entity-entity1)# common-name "tester1" device(config-pki-entity-entity1)# country-name "IN" device(config-pki-entity-entity1)# state-name "KA" device(config-pki-entity-entity1)# org-unit-name "FI" device(config-pki-entity-entity1)# org-name "Ruckus" device(config-pki-entity-entity1)# email-id "user@ruckus.com" device(config-pki-entity-entity1)# location "BG" device(config-pki-entity-entity1)# exit device(config)# pki profile-enrollment profile1 device(config-pki-profile-enrollment-profile1)# authentication-url http://WIN-N6C3R0LUDAJ.englab.ruckus.com/CertSrv/mscep/mscep.dll device(config-pki-profile-enrollment-profile1)# authentication-command WIN-N6C3R0LUDAJ.englab.ruckus.com_englab-WIN-N6C3R0LUDAJ-CA-15 device(config-pki-profile-enrollment-profile1)# enrollment-url http://WIN-N6C3R0LUDAJ.englab.ruckus.com/CertSrv/mscep/mscep.dll device(config-pki-profile-enrollment-profile1)# password DB6E1F091AEF0244 device(config-pki-profile-enrollment-profile1)# exit device(config)# pki trustpoint trust1 device(config-pki-trustpoint-trust1)# auto-enroll device(config-pki-trustpoint-trust1)# enrollment retry-period 2 device(config-pki-trustpoint-trust1)# enrollment profile profile1 device(config-pki-trustpoint-trust1)# pki-entity entity1 device(config-pki-trustpoint-trust1)# eckeypair key-label eckeyAuto device(config-pki-trustpoint-trust1)# fingerprint 36:0c:92:6e:df:b2:72:eb:59:e8:63:73:2a:98:a8:91:cb:50:94:d9 device(config-pki-trustpoint-trust1)# ocsp http post device(config-pki-trustpoint-trust1)# exit device(config)# pki authenticate trust1 device(config)# pki enroll trust1