Explains how to configure a wireless controller and LAP to use the locally significant certificate (LSC).
A locally significant certificate (LSC) is a PKI certificate that
-
provides mutual authentication between Cisco Catalyst 9800 Series Wireless Controller and Lightweight Access Points (LAPs)
-
generates certificates directly on APs and controllers, and
-
enables organizations to use their own PKI for better security control and Certificate Authority (CA) management.
LSC provisioning and communication process
You need to provision the new LSC certificate on the controller and then the Lightweight Access Point (LAP) from the CA Server.
The LAP communicates with the controller using the CAPWAP protocol. Any request to sign the certificate and issue the CA certificates for LAP and controller itself must be initiated from the controller. The LAP does not communicate directly with the CA server. The CA server details must be configured on the controller and must be accessible.
The controller makes use of the Simple Certificate Enrollment Protocol (SCEP) to forward certReqs generated on the devices to the CA and makes use of SCEP again to get the signed certificates from the CA.
The SCEP is a certificate management protocol that the PKI clients and CA servers use to support certificate enrollment and revocation. It is widely used in Cisco and supported by many CA servers. In SCEP, HTTP is used as the transport protocol for the PKI messages. The primary goal of SCEP is the secure issuance of certificates to network devices. SCEP is capable of many operations, but for our release, SCEP is utilized for the following operations:
-
CA and Router Advertisement (RA) Public Key Distribution
-
Certificate Enrollment