Details GUI-driven configuration tasks for PKI, including trustpoint authentication and enrollment, AP self-signed certificate generation, CA server addition, RSA or EC key setup, and certificate management, covering CSR generation and PKCS12 import procedures.
Generate an AP self-signed certificate (GUI)
-
Cisco Catalyst 9800-CL Wireless Controller for Cloud
-
Cisco Catalyst 9800-40 Wireless Controller
-
Cisco Catalyst 9800-80 Wireless Controller
-
Cisco Catalyst 9800-L Wireless Controller (Copper uplink)
-
Cisco Catalyst 9800-L Wireless Controller (Fiber uplink)
Procedure
-
Choose .
-
In the AP SSC Trustpoint area, click Generate to generate an AP SSC trustpoint.
-
From the RSA Key-Size drop-down list, choose a key size.
-
From the Signature Algorithm drop-down list, choose an option.
-
From the Password Type drop-down list, choose a password type.
-
In the Password field, enter a password. The valid range is between 8 and 32 characters.
-
Click Apply to Device.
Add the CA server (GUI)
Add an RSA or EC Key for PKI trustpoint (GUI)
Procedure
Add and manage certificates
To add and manage certificates, use one of these methods.
Generate and import a certificate signing request (CSR)
Before you begin
-
When configuring a password for the .pfx file, avoid using these ASCII characters: "*, ^, (), [], \, ", and +". Using these ASCII characters results in a configuration error and prevents the certificate from being imported to the controller.
-
Ensure you have the required certificate files and CA information.
Before you begin
You can add and manage certificates using either of the following methods:Procedure
Import a PKCS12 certificate
Import a PKCS12 certificate into the system to enable secure authentication and encryption for network communications.
Use this task when you need to install a PKCS12 certificate file for system, server, or application authentication.
The certificate can be located on any of these sources: FTP, SFTP, TFTP, SCP, or Desktop (HTTPS).Before you begin
Obtain the PKCS12 certificate file and its password.
Procedure
-
Click Import PKCS12 Certificate.
-
From the Transport Type drop-down list, choose either FTP, SFTP, TFTP, SCP, or Desktop (HTTPS).
Transport Type Action For FTP, SFTP, and
SCPenter values in the Server IP Address (IPv4/IPv6), Username, Password, Certificate File Path, Certificate Destination File Name, and Certificate Password fields. For TFTP enter values in the Server IP Address (IPv4/IPv6), Certificate File Path, Certificate Destination File Name, and Certificate Password fields. For Desktop (HTTPS) enter values in the Source File Path and Certificate Password fields. -
Click Import.
The system imports the PKCS12 certificate. You see a confirmation message when the process completes successfully.