Creating a Trustpoint

A CA is called a trustpoint because you implicitly trust its authority. The idea is that by trusting a given self-signed certificate, your PKI system will automatically trust any other certificates signed with that trusted certificate. The configuration of multiple trustpoints is supported, and the system supports configuration of up to 10 trustpoints.

Enter the pki trustpoint command to configure a PKI trustpoint and enter trustpoint configuration mode.

device(config)# pki trustpoint ruckus
device(config-pki-trustpoint-ruckus)#

PKI functionality is configured and setup using the following commands.

device(config)# pki entity entity1
device(config-pki-entity-entity1)# common-name ruckus
device(config-pki-entity-entity1)# org-unit-name FI
device(config-pki-entity-entity1)# org-name RUCKUS
device(config-pki-entity-entity1)# state-name KA
device(config-pki-entity-entity1)# country-name IN
device(config-pki-entity-entity1)# email-id user@ruckus.com
device(config-pki-entity-entity1)# location BG

The crypto key generate command offers different methods of generating key-pairs. The following code sample shows the command options available for key generation.

device# configure terminal
device(config)# crypto key generate ?
  ec        generate elliptical key pair for PKI
  rsa       generate rsa key pair
  <cr>
device(config)# crypto key generate rsa ?
  label     input rsa label
  modulus   generate rsa key size 2048
  <cr>

The following example creates enrollment profile profile1 that is added to the configuration for the trustpoint trust1. The trust1 configuration uses an eckeypair with the label ec_2 that was previously generated with the crypto key generate ec command.

device# configure terminal
device(config)# pki profile-enrollment profile1
device(config-pki-profile-enrollment-profile1)# authentication-url http://FI-PKI02.englab.ruckus.com/CertSrv/mscep/mscep.dll
device(config-pki-profile-enrollment-profile1)# enrollment-url http://FI-PKI02.englab.ruckus.com/CertSrv/mscep/mscep.dll

device(config)#pki trustpoint trust1
device(config-pki-trustpoint-trust1)# enrollment retry-count 3
device(config-pki-trustpoint-trust1)# enrollment retry-period 2
device(config-pki-trustpoint-trust1)# enrollment profile profile1
device(config-pki-trustpoint-trust1)# pki-entity entity1
device(config-pki-trustpoint-trust1)# revocation-check crl
device(config-pki-trustpoint-trust1)# crl-query http://FI-PKI02.englab.ruckus.com/CertEnroll/englab-FI-PKI02-CA.crl
device(config-pki-trustpoint-trust1)# crl-update-time 1
device(config-pki-trustpoint-trust1)# eckeypair key-label ec_2
device(config-pki-trustpoint-trust1)# fingerprint 89:31:79:bd:50:55:ef:84:7f:0c:ae:9a:5c:12:d7:7b:fa:3b:d1:d8

device(config)#ikev2 auth-proposal a1
device(config-ike-auth-proposal-a1)# method remote ecdsa384
device(config-ike-auth-proposal-a1)# method local ecdsa384
device(config-ike-auth-proposal-a1)# pki-trustpoint trust1 sign
device(config-ike-auth-proposal-a1)# pki-trustpoint trust1 verify

The following example configures the IKEv2 authentication proposal a1, which uses trustpoint trust1 to sign and verify certificates.

device(config)# ikev2 auth-proposal a1
device(config-ike-auth-proposal-a1)# method remote ecdsa384
device(config-ike-auth-proposal-a1)# method local ecdsa384
device(config-ike-auth-proposal-a1)# pki-trustpoint trust1 sign
device(config-ike-auth-proposal-a1)# pki-trustpoint trust1 verify

The following authentication algorithms can also be configured apart from ecdsa384:

  • ecdsa256
  • rsa
  • rsa2048
  • pre-shared

If pre-shared is selected, PKI functionality is not used. Instead, the pre-shared key is used to negotiate with peers, in which case, both endpoints must have the same pre-shared key configured.

The pki authenticate command is used to authenticate the trustpoint. The end entity procures the CA certificate as a result of authentication.

device(config)# pki authenticate <trustpoint-name>

The pki enroll command is used to enroll the trustpoint with the CA server. The end entity procures its local certificate with a digital signature from the CA server as a result of enrollment.

device(config)# pki enroll <trustpoint-name>

The certificates for the end entity can be generated using PKI infrastructure or can be pre-generated and copied offline into the flash of the device.

The following commands are used to import stored certificates from the flash of the device.

device(config)# pki import trust1 pem url flash: <root-ca-file-name>.pem
device(config)# pki import trust1 pem url flash: <end-entity-file-name>.pem
device(config)# pki import key ec <key-label> pem url flash: <end-entity-key-file-name>.pem
device(config)# pki import key rsa <key-label> pem url flash: <end-entity-key-file-name>.pem

The following commands are available to display information from the PKI database.

device# show pki
  certificates         	Display pki certificates
  counters            	 Show PKI counters
  crls			               Show PKI Certification Revocation list if Any
  enrollment-profile   	Show PKI enrollment profile.
  entity               	Show PKI entity.
  key                  	Show router public keys.
  logging-statistics   	Display pki logging statistics
  trustpoint           	Show  PKI trustpoint information

The following show pki certificates commands are used to display the certificate information associated with specific trustpoints in the PKI database.

device# show pki certificates trustpoint <trustpoint-name>
device# show pki certificates trustpoint <trustpoint-name> detail
device# show pki certificates local trustpoint <trustpoint-name>
device# show pki certificates local trustpoint <trustpoint-name> detail