![]() |
Cisco Secure VPN Client Solutions Guide
|
||||||||||||||||||||
Configuring Entrust Digital Certificates
![]() |
|||||||||||||||||||||
|
Table of ContentsConfiguring Entrust Digital CertificatesConfiguring Entrust Digital CertificatesThis appendix provides additional information on requesting digital certification from the Entrust CA server and configuring ca-identity configuration commands on your gateway. Use this appendix with "Configuring Digital Certification," and the enrollment procedures on the Entrust web site. Entrust Certificate AuthorityThis CA requires that both IPSec peers transact with a Registration Authority (RA), which then forwards the requests through to the CA. Both the remote IPSec peer and the local IPSec peer must be configured with the both the CA and RA public keys. The CA and RA public keys are signature and encryption key pairs, which must be generated and enrolled for authentication to occur. For information on configuring Entrust CA, see the following URLs:
Figure A-1: Entrust CA Server Topology
Configuring Entrust CA Identity on the GatewayThis step corresponds to the "Declaring the CA" section in "Configuring Digital Certification." To enroll your certificate with a CA, perform the following tasks, as described in Table A-1:
Table A-1: Declare the CA
|
||||||||||||||||||||
|
|