Explains the purpose, issuance, and management of web server certificates in Cisco SD-WAN environments.
A web server certificate is a digital authentication credential that
-
ensures secure access to the web server,
-
is issued via a Certificate Signing Request (CSR) signed by a trusted Certificate Authority (CA), and
-
is associated with a specific DNS name for the deployment environment.
Certificate generation and deployment requirements
Web server certificates are not automatically issued for Cisco SD-WAN Manager. Generate the Certificate Signing Request (CSR) and get it signed by your Certificate Authority (CA) for your Domain Name System (DNS) name. For commercial deployments, add an A entry in your DNS server for the IP address, or add a CNAME to the .viptela.net or .sdwan.cisco.com Cisco SD-WAN Manager DNS name. For government deployments, use sdwangov.fedramp.cisco.
Control component certificates are for internal control component use only. Use web server certificates for web server authentication.
Refer to "Web Server Certificates" in the Cisco Catalyst SD-WAN Getting Started Guide for more information.