Explains how Enrollment over Secure Transport uses TLS to secure certificate provisioning and automate certificate renewal for configured trustpoints.
Enrollment over Secure Transport (EST) is a digital certificate provisioning protocol that
-
uses TLS to secure certificate provisioning communication
-
supports designated certificate requestors, and
-
automates certificate renewal.
|
Feature Name |
Release Information |
Feature Description |
|---|---|---|
|
EST protocol for automated certificate provisioning |
Release 26.1.1 |
Introduced in this release on: Centralized Systems (8400 [ASIC: K100])(select variants only*) * This feature is now supported on Cisco 8404-SYS-D routers. |
|
EST protocol for automated certificate provisioning |
Release 25.1.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: Q200, P100], 8700 [ASIC: P100, K100]); Centralized Systems (8600 [ASIC: Q200]); Modular Systems (8800 [LC ASIC: Q100, Q200, P100]) This release introduces support for Enrollment Over Secure Transport (EST), a digital certificate provisioning protocol, which enhances certificate management by offering secure transport using TLS and designated certificate requestors. It enables automated certificate renewal. EST is an enhancement of the existing Simple Certificate Enrollment Protocol (SCEP), providing improved security and flexibility for certificate management operations over both IPv4 and IPv6 networks. The feature introduces these changes: CLI:
YANG Data Model:
(see GitHub, YANG Data Models Navigator) |