Creating a PKI Enrollment Profile

You can create a PKI enrollment profile you can use to efficiently enroll requester systems. When you create a profile, you name the profile and specify the values for the parameters used to enroll requester systems. Once the profile is defined, you can use it to enroll requester systems.

To define an enrollment profile, enter the pki profile-enrollment command in global configuration mode. Using this command enters pki-profile mode, which is required to configure the enrollment profile parameters.

Use the no form of this command to delete all information defined in the enrollment profile.

Note: You must specify the authentication and enrollment URLs in the correct form. The URL argument must be in the form http://CA_name, where CA_name is the host Domain Name System (DNS) name or IP address of the CA.

To create a PKI enrollment profile, do the following:

  1. Enter the pki profile-enrollment command.
    device(config)# pki profile-enrollment
  2. Use the following parameters to specify values for the enrollment profile:
    • name: The name of the profile.
    • authentication-url url-string: The URL of the certification authority (CA) server you want to receive the authentication requests. Make sure you use the correct form of the URL.

    • (Optional) authentication-command url-string: The HTTP command that is sent to the certification authority (CA) for authentication.

      authentication command GET /certs/cacert.der

    • enrollment-url url-string: The URL of the certification authority (CA) server you want to receive the enrollment requests. Make sure you use the correct form of the URL.

    • (Optional) password: The password for the SCEP challenge used to revoke the requester's current certificate and issue another certificate for auto mode. No default value is configured.