K
K
kaw19942021-04-08 15:40:39
System administration
kaw1994, 2021-04-08 15:40:39

How to issue a single certificate using ADCS for all switches or other equipment?

How to issue a single certificate using ADCS for all switches or other equipment?
Tell me where to dig.
Given:
A lot of equipment to which I would like to connect via an encrypted channel, but adding each piece of hardware to AD CS will take too much time.
Tell me, can there be a way to issue one certificate, and then distribute it?

Answer the question

In order to leave comments, you need to log in

3 answer(s)
A
Alexey Dmitriev, 2021-04-08
@SignFinder

1. Create a subzone in DNS - for example nethw.%companydomain.local%.
2. Create DNS entries in it for each device in order to address them by DNS name.
3. Issue wilcard certificate for *.nethw.companydomain.local
4. Add it to all devices.

C
CityCat4, 2021-04-08
@CityCat4

No way. And there is no need.
Certificates are not a noob topic and never will be. Any piece of iron can generate self-signed - nafig you don’t need to put a generated one on it - it only adds crap and the switch can hang up. And the procedure for installing a certificate on different switches is very different from each other.
Putting generated certificates is only from the desire to go to the glands by the beautiful name "switch1-1-1.zhopa.ruchka", and not at the address - otherwise there is no point. And for beauty - all switches must first be entered in DNS, to support it. Yes, this can be done if there is nothing else

Z
zvl, 2021-04-15
@zvl

In order not to bother with ADCS, you can use XCA.
Import the generated XCA root certificate into the domain root store by executing the command as a domain administrator on any domain member computer:
certutil -f -dspublish "DOMAIN ROOT CA.crt"
RootCA devices. The new domain includes suffixes of the network interface in DNS by domain policies.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question