Configuring PKI
PKI configuration enables you to set up the elements responsible for managing the
keys and certificates used to identify and authenticate system requesters and essential
PKI elements (such as CAs).
PKI configuration involves a number of tasks, including creating PKI entities and trustpoints, generating and installing certificate requests, and authenticating PKI elements. Creating an enrollment profile is an optional task.
In this section:
- Configuring an Entity Distinguished NameA certificate is the combination of a public key and the identity information of an entity, where the CA identifies a certificate applicant and the identity information using an entity Distinguished Name (DN).
- Creating a TrustpointA CA is called a trustpoint because you implicitly trust its authority. The idea is that by trusting a given self-signed certificate, your PKI system will automatically trust any other certificates signed with that trusted certificate. The configuration of multiple trustpoints is supported, and the system supports configuration of up to 10 trustpoints.
- Configuring CA AuthenticationYour router authenticates the CA by obtaining the CA self-signed certificate (this certificate contains the public key of the CA). Because the CA signs its own certificate, you should manually authenticate the public key of the CA by contacting the CA administrator when you enter the command to authenticate the CA. The certificate obtained from the CA is saved to the router.
- Generating a Certificate RequestYour router requests certificates from the CA (trustpoint) to be added to each key pair of your router. This enrolls the router on the CA trustpoint. You use a single command to request the certificate. The certificates are saved to the router.
- Extended Key UsageExtended Key Usage (EKU) is a method of enforcing the public key of a certificate to be used for a pre-determined set of key purposes.
- Creating a PKI Enrollment ProfileYou can create a PKI enrollment profile you can use to efficiently enroll requester systems. When you create a profile, you name the profile and specify the values for the parameters used to enroll requester systems. Once the profile is defined, you can use it to enroll requester systems.
- Installing Identity CertificatesManually installs (by import) certificates from the flash memory of the CA trustpoint to the system requester (router). You specify the trustpoint by name that issues the certificates the system requester imports. One command is used to specify the CA trustpoint and another command is used to export the already-imported certificates to the CA. Exporting certificates ensures that they can be used again if the router is rebooted.
- Clearing the Certificate Revocation List (CRL) and PKI Counters
- Enabling PKI Logging
- Displaying PKI InformationDisplay PKI information including, certificates, CA status, certificate evocation lists, PKI counters, public keys, and current enrollment profiles, and PKI entities.
Parent topic: PKI Support for IPsec