Configures EST authentication, PKI trustpoints, certificate enrollment, and certificate verification for secure automated provisioning.
Configure the EST protocol on the router to enable secure and automated certificate provisioning.
Before you begin
Before configuring EST, ensure that:
-
Access to the EST server is established and operational.
-
The certificates and keys required for configuration are available.
-
For HTTP-based authentication, create an RSA key with the crypto key generate rsa key command and use the generated key to configure the EST trustpoint.
-
Enable Type 6 encryption with the password6 encryption aes command for secure password handling.
-
Create a master key and store it in the Trust Anchor Module (TAM) with the key config-key password-encryption command.
A master key for Type 6 encryption is stored in the device internal memory in a protected area known as the TAM.
Procedure
The router uses EST to authenticate the server, enroll certificates, and verify the resulting certificate chain on the configured trustpoint.