![]() |
Cisco Secure VPN Client Solutions Guide
|
||||||||||||||||||||
Configuring Microsoft Certificate Services
![]() |
|||||||||||||||||||||
|
Table of ContentsConfiguring Microsoft Certificate ServicesConfiguring Microsoft Certificate ServicesThis appendix provides additional information on requesting digital certification from the Microsoft CA server and configuring ca-identity configuration commands on your gateway. Use this appendix with "Configuring Digital Certification." Microsoft Certificate ServicesThis CA requires that both IPSec peers transact with a Registration Authority (RA), which then forwards the requests through to the CA. Both the remote IPSec peer and the local IPSec peer must be configured with the both the CA and RA public keys. The CA and RA public keys are signature and encryption key pairs, which must be generated and enrolled for authentication to occur. For information on configuring Microsoft Certificate Services, see the following URLs:
Figure B-1: Microsoft CA Server Topology
Configuring Microsoft CA Identity on GatewayThis step corresponds to "Declaring the CA" in "Configuring Digital Certification." To enroll your certificate with a Microsoft CA, perform the following tasks, as described in Table B-1:
Table B-1: Declare the CA
|
||||||||||||||||||||
|
|