Details GUI-driven configuration tasks for PKI, including trustpoint authentication and enrollment, AP self-signed certificate generation, CA server addition, RSA or EC key setup, and certificate management, covering CSR generation and PKCS12 import procedures.
Generate an AP self-signed certificate (GUI)
-
Cisco Catalyst 9800-CL Wireless Controller for Cloud
-
Cisco Catalyst 9800-40 Wireless Controller
-
Cisco Catalyst 9800-80 Wireless Controller
-
Cisco Catalyst 9800-L Wireless Controller (Copper uplink)
-
Cisco Catalyst 9800-L Wireless Controller (Fiber uplink)
Procedure
| 1. | Choose . |
|
| 2. | In the AP SSC Trustpoint area, click Generate to generate an AP SSC trustpoint. |
|
| 3. | From the RSA Key-Size drop-down list, choose a key size. |
|
| 4. | From the Signature Algorithm drop-down list, choose an option. |
|
| 5. | From the Password Type drop-down list, choose a password type. |
|
| 6. | In the Password field, enter a password. The valid range is between 8 and 32 characters. |
|
| 7. | Click Apply to Device. |
Add the CA server (GUI)
Procedure
| 1. | Choose . |
|
| 2. | In the PKI Management window, click the CA Server tab. |
|
| 3. | In the CA Server section, click the Shutdown Status to enable the status. If you choose the shutdown status as Enabled, enter and confirm the password. |
|
| 4. | If you choose the shutdown status as Disabled, you must enter the Country Code, State, Location, Organization, Domain Name, and Email Address. |
|
| 5. | Click Apply to add the CA server. |
|
| 6. | Click Remove CA Server to delete the CA server. |
Add an RSA or EC Key for PKI trustpoint (GUI)
Procedure
| 1. | Choose . |
|
| 2. | In the PKI Management window, click the Key Pair Generation tab. |
|
| 3. | In the Key Pair Generation section, click Add. |
|
| 4. | In the dialog box that is displayed, provide this information:
|
Add and manage certificates
To add and manage certificates, use one of these methods.
Generate and import a certificate signing request (CSR)
Before you begin
-
When configuring a password for the .pfx file, avoid using these ASCII characters: "*, ^, (), [], \, ", and +". Using these ASCII characters results in a configuration error and prevents the certificate from being imported to the controller.
-
Ensure you have the required certificate files and CA information.
Before you begin
You can add and manage certificates using either of the following methods:Procedure
| 1. | Choose Configuration > Security > PKI Management > Add Certificate. |
|
| 2. | Click Generate Certificate Signing Request.
|
|
| 3. | Click Authenticate Root CA. |
|
| 4. | Click Import Device Certificate.
|
Import a PKCS12 certificate
Import a PKCS12 certificate into the system to enable secure authentication and encryption for network communications.
Use this task when you need to install a PKCS12 certificate file for system, server, or application authentication.
The certificate can be located on any of these sources: FTP, SFTP, TFTP, SCP, or Desktop (HTTPS).Before you begin
Obtain the PKCS12 certificate file and its password.
Procedure
| 1. | Click Import PKCS12 Certificate. |
|||||||||
| 2. | From the Transport Type drop-down list, choose either FTP, SFTP, TFTP, SCP, or Desktop (HTTPS).
|
|||||||||
| 3. | Click Import. |
The system imports the PKCS12 certificate. You see a confirmation message when the process completes successfully.