Details the configuration, provisioning, management, and verification of locally significant certificates (LSCs), including RSA key and PKI trustpoint setup, certificate enrollment, AP LSC provisioning, trustpool management, and secure wireless network authentication using both GUI and CLI procedures.
Configure RSA key for PKI trustpoint
Before you begin
Ensure the device is in a stable operational state and has sufficient processing resources for key generation.Procedure
Configure PKI trustpoint parameters
Before you begin
Ensure the CA server is accessible and configured to accept certificate requests.Procedure
Authenticate and enroll a Public Key Infrastructure (PKI) trustpoint (GUI)
Before you begin
Obtain the enrollment URL and certificate authority information from your network administrator.Procedure
What to do next
After enrolling the trustpoint, configure it for use with your security policies or certificate-based authentication features.
Authenticate and enroll the PKI trustpoint with CA server (CLI)
Before you begin
Ensure the PKI trustpoint is configured and the CA server is accessible.Procedure
Configure AP join attempts with LSC certificate
Procedure
-
Choose .
-
In the All Access Points window, click the LSC Provision name.
-
From the Status drop-down list, choose a status to enable LSC.
-
From the Trustpoint Name drop-down list, choose the trustpoint.
-
In the Number of Join Attempts field, enter the number of retry attempts that will be permitted.
-
Click Apply.
Configure AP join attempts with LSC certificate (CLI)
Procedure
Configure subject-name parameters in LSC certificate
Procedure
Configure key size for LSC certificate
Procedure
Configure trustpoint for LSC provisioning on an AP
Before you begin
Ensure the trustpoint is properly configured and accessible on the network.Procedure
Configure an AP LSC provision list (GUI)
Procedure
Configure an AP LSC provision list (CLI)
Procedure
Configure LSC provisioning for all the APs (GUI)
Procedure
Configure LSC provisioning for all APs (CLI)
Before you begin
Ensure you have administrative access to the wireless controller and that all APs are properly registered with the controller.Procedure
Configure LSC provisioning for the APs in the provision list
Procedure
Import a CA certificate to the trustpool (GUI)
PKI Trustpool Management is used to store a list of trusted certificates (either downloaded or built in) used by the different services on the controller. This is also used to authenticate a multilevel CA certificate. The built in CA certificate bundle in the PKI trustpool receives automatic updates from Cisco if they are not current, are corrupt, or if certain certificates need to be updated.
Perform this task to manually update the CA certificates in the PKI trustpool.
If your LSC has been issued by an intermediate CA, you must import the complete chain of CA certificates into the trustpool. Otherwise, you will not be able to provision the APs without the complete chain being present on the controller. The import step is not required if the certificate has been issued by a root CA.
Follow these steps to import a CA certificate to the trustpool using GUI:
Procedure
-
Choose .
-
In the PKI Management window, click the Trustpool tab.
-
Click Import.
-
In the CA Certificate field, copy and paste the CA certificate. Link together the multiple CA certificates in .pem format.
-
Click Apply to Device.
Import a CA certificate to the trustpool
Procedure
Clean the CA certificates imported in trustpool (GUI)
Procedure
Clean CA certificates imported in trustpool (CLI)
You cannot delete a specific CA certificate from the trustpool. However, you can clear all the CA certificates that are imported to the Trustpool.
Procedure
Create a new trustpoint dedicated to a single CA certificate
Procedure
Verify LSC configuration
Use show commands to verify Local Security Certificate (LSC) configuration. View wireless management trustpoint details and Local Security Certificate (LSC) provision-related configuration for your access points.
To view the wireless management trustpoint details, use this command:
Device# show wireless management trustpoint
Trustpoint Name : microsoft-ca
Certificate Info : Available
Certificate Type : LSC
Certificate Hash : 9e5623adba5307facf778e6ea2f5082877ea4beb
Private key Info : Available
To view the Local Security Certificate (LSC) provision-related configuration details for an AP, use this command:
Device# show ap lsc-provision summary
AP LSC-provisioning : Disabled
Trustpoint used for LSC-provisioning : lsc-root-tp
Certificate chain status : Available
Number of certs on chain : 2
Certificate hash : 7f9d05183deecac4e5a79db65d538245685e8e30
LSC Revert Count in AP reboots : 1
AP LSC Parameters :
Country : IN
State : KA
City : BLR
Orgn : ABC
Dept : ABC
Email : support@abc.com
Key Size : 2048
EC Key Size : 384 bit
AP LSC-provision List :
Total number of APs in provision list: 2
Mac Addresses :
--------------
1880.90f5.1540
2c5a.0f70.84dc
Configure management trustpoint to LSC
Procedure
-
Choose .
-
In the HTTP Trust Point Configuration section, set Enable Trust Point to the Enabled state.
-
From the Trust Points drop-down list, choose the appropriate trustpoint.
-
Save the configuration.
Configure management trustpoint to LSC (CLI)
After LSC provisioning, the APs will automatically reboot and join at the LSC mode after bootup. Similarly, if you remove the AP LSC provisioning, the APs reboot and join at non-LSC mode.