Details the configuration, provisioning, management, and verification of locally significant certificates (LSCs), including RSA key and PKI trustpoint setup, certificate enrollment, AP LSC provisioning, trustpool management, and secure wireless network authentication using both GUI and CLI procedures.
Configure RSA key for PKI trustpoint
Before you begin
Ensure the device is in a stable operational state and has sufficient processing resources for key generation.Procedure
| 1. | Enter global configuration mode. Example:
|
|
| 2. | Generate RSA key for PKI trustpoint. Example:
Example:
exportable is an optional keyword. You may or may not want to configure an exportable-key. If selected, you can export the key out of the box, if required.
|
|
| 3. | Return to privileged EXEC mode. Example:
|
Configure PKI trustpoint parameters
Before you begin
Ensure the CA server is accessible and configured to accept certificate requests.Procedure
| 1. | Enter global configuration mode. Example:
|
|
| 2. | Create a new trustpoint for an external CA server. Example:
Example:
The trustpoint-name refers to the trustpoint name. |
|
| 3. | Specify the URL of the CA on which your router should send certificate requests. Example:
Example:
HTTP-URL: URL of the file system where your router should send certificate requests. An IPv6 address can be added in the URL enclosed in brackets. For example: http://[2001:DB8:1:1::1]:80. For more enrollment method options, see the enrollment url (ca-trustpoint) command page. |
|
| 4. | Create subject name parameters for the trustpoint. Example:
Example:
|
|
| 5. | Map RSA key with that of the trustpoint. Example:
Example:
|
|
| 6. | Configure revocation checking method. Example:
Example:
|
|
| 7. | Return to privileged EXEC mode. Example:
|
Authenticate and enroll a Public Key Infrastructure (PKI) trustpoint (GUI)
Before you begin
Obtain the enrollment URL and certificate authority information from your network administrator.Procedure
| 1. | Choose . |
|
| 2. | In the Public Key Infrastructure (PKI) Management window, click the Trustpoints tab. |
|
| 3. | In the Add Trustpoint dialog box, provide this information:
The new trustpoint is added to the trustpoint name list.
|
What to do next
After enrolling the trustpoint, configure it for use with your security policies or certificate-based authentication features.
Authenticate and enroll the PKI trustpoint with CA server (CLI)
Before you begin
Ensure the PKI trustpoint is configured and the CA server is accessible.Procedure
| 1. | Enter global configuration mode. Example:
|
|
| 2. | Fetch the CA certificate. Example:
Example:
|
|
| 3. | Accept the CA certificate. Example:
|
|
| 4. | Enroll the client certificate. Example:
Example:
|
|
| 5. | Enter a challenge password to the CA server. Example:
Example:
|
|
| 6. | Re-enter the challenge password to the CA server. Example:
Example:
|
|
| 7. | Include the router serial number in the subject name. Example:
|
|
| 8. | Exclude IP address from the subject name. Example:
|
|
| 9. | Request certificate from CA. Example:
|
|
| 10. | Return to privileged EXEC mode. Example:
|
Configure AP join attempts with LSC certificate
Procedure
| 1. | Choose . |
|
| 2. | In the All Access Points window, click the LSC Provision name. |
|
| 3. | From the Status drop-down list, choose a status to enable LSC. |
|
| 4. | From the Trustpoint Name drop-down list, choose the trustpoint. |
|
| 5. | In the Number of Join Attempts field, enter the number of retry attempts that will be permitted. |
|
| 6. | Click Apply. |
Configure AP join attempts with LSC certificate (CLI)
Procedure
| 1. | Enter global configuration mode. Example:
|
|
| 2. | Specify the maximum number of AP join failure attempts with the newly provisioned LSC certificate. Example:
Example:
When the number of AP joins exceed the specified limit, AP joins back with the Manufacturer Installed Certificate (MIC). |
|
| 3. | Return to privileged EXEC mode. Example:
Alternatively, you can also press Ctrl-Z to exit global configuration mode. |
Configure subject-name parameters in LSC certificate
Procedure
| 1. | Enter global configuration mode. Example:
|
|
| 2. | Specify the attributes to be included in the subject-name parameter of the certificate request generated by an AP. Example:
Example:
|
|
| 3. | Return to privileged EXEC mode. Example:
|
Configure key size for LSC certificate
Procedure
| 1. | Enter global configuration mode. Example:
|
|
| 2. | Specify the size of keys to be generated for the LSC on AP. Example:
Example:
Valid key size options are 2048, 3072, or 4096 bits. |
|
| 3. | Return to privileged EXEC mode. Example:
Alternatively, you can also press Ctrl-Z to exit global configuration mode. |
Configure trustpoint for LSC provisioning on an AP
Before you begin
Ensure the trustpoint is properly configured and accessible on the network.Procedure
| 1. | Enter global configuration mode. Example:
|
|
| 2. | Specify the trustpoint with which the LSC is provisioned to an AP. Example:
Example:
The tp-name is the trustpoint name. |
|
| 3. | Return to privileged EXEC mode. Example:
|
Configure an AP LSC provision list (GUI)
Procedure
| 1. | Choose . |
|
| 2. | In the All Access Points window, click the corresponding LSC Provision name. |
|
| 3. | From the Status drop-down list, choose a status to enable LSC. |
|
| 4. | From the Trustpoint Name drop-down list, choose a trustpoint. |
|
| 5. | In the Number of Join Attempts field, enter the number of retry attempts that are allowed. |
|
| 6. | From the Key Size drop-down list, choose a key. |
|
| 7. | In the Edit AP Join Profile window, click the CAPWAP tab. |
|
| 8. | In the Add APs to LSC Provision List section, click Select File to upload the CSV file that contains AP details. |
|
| 9. | Click Upload File. |
|
| 10. | In the AP MAC Address field, enter the AP MAC address. and add them. (The APs added to the provision list are displayed in the APs in provision List .) |
|
| 11. | In the Subject Name Parameters section, enter the following details:
|
|
| 12. | Click Apply. |
Configure an AP LSC provision list (CLI)
Procedure
| 1. | Enter global configuration mode. Example:
|
|
| 2. | Add the AP to the LSC provision list. Example:
Example:
|
|
| 3. | Return to privileged EXEC mode. Example:
|
Configure LSC provisioning for all the APs (GUI)
Procedure
| 1. | Choose . |
|
| 2. | In the Access Points window, expand the LSC Provision section. |
|
| 3. | Set Status to Enabled state.
|
|
| 4. | From the Trustpoint Name drop-down list, choose the appropriate trustpoint for all APs. |
|
| 5. | In the Number of Join Attempts field, enter the number of retry attempts that the APs can make to join the controller. |
|
| 6. | From the Key Size drop-down list, choose the appropriate key size of the certificate:
|
|
| 7. | In the Add APs to LSC Provision List section, click Select File to upload the CSV file that contains the AP details. |
|
| 8. | Click Upload File. |
|
| 9. | In the AP MAC Address field, enter the AP MAC address. (The APs that are added to the provision list are displayed in the APs in Provision List section.) |
|
| 10. | In the Subject Name Parameters section, enter the following details:
|
|
| 11. | Click Apply. |
Configure LSC provisioning for all APs (CLI)
Before you begin
Ensure you have administrative access to the wireless controller and that all APs are properly registered with the controller.Procedure
| 1. | Enter global configuration mode. Example:
|
|
| 2. | Enable LSC provisioning for all APs. Example:
By default, LSC provisioning is disabled for all APs. |
|
| 3. | Return to privileged EXEC mode. Example:
|
Configure LSC provisioning for the APs in the provision list
Procedure
| 1. | Enter global configuration mode. Example:
|
|
| 2. | Enable LSC provisioning for a set of APs configured in the provision list. Example:
|
|
| 3. | Return to privileged EXEC mode. Example:
Alternatively, you can also press Ctrl-Z to exit global configuration mode. |
Import a CA certificate to the trustpool (GUI)
PKI Trustpool Management is used to store a list of trusted certificates (either downloaded or built in) used by the different services on the controller. This is also used to authenticate a multilevel CA certificate. The built in CA certificate bundle in the PKI trustpool receives automatic updates from Cisco if they are not current, are corrupt, or if certain certificates need to be updated.
Perform this task to manually update the CA certificates in the PKI trustpool.
If your LSC has been issued by an intermediate CA, you must import the complete chain of CA certificates into the trustpool. Otherwise, you will not be able to provision the APs without the complete chain being present on the controller. The import step is not required if the certificate has been issued by a root CA.
Follow these steps to import a CA certificate to the trustpool using GUI:
Procedure
| 1. | Choose . |
|
| 2. | In the PKI Management window, click the Trustpool tab. |
|
| 3. | Click Import. |
|
| 4. | In the CA Certificate field, copy and paste the CA certificate. Link together the multiple CA certificates in .pem format. |
|
| 5. | Click Apply to Device. |
Import a CA certificate to the trustpool
Procedure
| 1. | Enter global configuration mode. Example:
|
|
| 2. | Import the root certificate to the trustpool. Example:
You need to paste the CA certificate from the digicert.com. |
|
| 3. | Return to privileged EXEC mode. Example:
|
Clean the CA certificates imported in trustpool (GUI)
Procedure
| 1. | Choose . |
|
| 2. | In the PKI Management window, click the Trustpool tab. |
|
| 3. | Click Clean.
|
|
| 4. | Click Yes. |
Clean CA certificates imported in trustpool (CLI)
You cannot delete a specific CA certificate from the trustpool. However, you can clear all the CA certificates that are imported to the Trustpool.
Procedure
| 1. | Enter global configuration mode. Example:
|
|
| 2. | Erase the downloaded CA certificate bundles. Example:
This command does not erase the built-in CA certificate bundles. |
|
| 3. | Return to privileged EXEC mode. Example:
Alternatively, you can also press Ctrl-Z to exit global configuration mode. |
Create a new trustpoint dedicated to a single CA certificate
Procedure
| 1. | Enter global configuration mode. Example:
|
|
| 2. | Create a trustpoint. Example:
Example:
|
|
| 3. | Create an enrollment terminal for the trustpoint. Example:
|
|
| 4. | Exit from the trustpoint configuration. Example:
|
|
| 5. | Authenticate the trustpoint. Example:
Example:
|
Verify LSC configuration
Use show commands to verify Local Security Certificate (LSC) configuration. View wireless management trustpoint details and Local Security Certificate (LSC) provision-related configuration for your access points.
To view the wireless management trustpoint details, use this command:
Device# show wireless management trustpoint
Trustpoint Name : microsoft-ca
Certificate Info : Available
Certificate Type : LSC
Certificate Hash : 9e5623adba5307facf778e6ea2f5082877ea4beb
Private key Info : Available
To view the Local Security Certificate (LSC) provision-related configuration details for an AP, use this command:
Device# show ap lsc-provision summary
AP LSC-provisioning : Disabled
Trustpoint used for LSC-provisioning : lsc-root-tp
Certificate chain status : Available
Number of certs on chain : 2
Certificate hash : 7f9d05183deecac4e5a79db65d538245685e8e30
LSC Revert Count in AP reboots : 1
AP LSC Parameters :
Country : IN
State : KA
City : BLR
Orgn : ABC
Dept : ABC
Email : support@abc.com
Key Size : 2048
EC Key Size : 384 bit
AP LSC-provision List :
Total number of APs in provision list: 2
Mac Addresses :
--------------
1880.90f5.1540
2c5a.0f70.84dc
Configure management trustpoint to LSC
Procedure
| 1. | Choose . |
|
| 2. | In the HTTP Trust Point Configuration section, set Enable Trust Point to the Enabled state. |
|
| 3. | From the Trust Points drop-down list, choose the appropriate trustpoint. |
|
| 4. | Save the configuration. |
Configure management trustpoint to LSC (CLI)
After LSC provisioning, the APs will automatically reboot and join at the LSC mode after bootup. Similarly, if you remove the AP LSC provisioning, the APs reboot and join at non-LSC mode.
Procedure
| 1. | Enter global configuration mode. Example:
|
|
| 2. | Configure the management trustpoint to LSC. Example:
Example:
|
|
| 3. | Return to privileged EXEC mode. Example:
Alternatively, you can also press Ctrl-Z to exit global configuration mode. |