Answer the question
In order to leave comments, you need to log in
Trouble getting a certificate on the router?
Colleagues, good day. A strange situation has arisen. There is cisco 881. Firmware c880data-universalk9-mz.151-4.M1.bin
. It has a Windows Certificate Authority (SCEP) configured on it.
crypto pki trustpoint RootCA
enrollment mode ra
enrollment url http://192.168.1.1:80/certsrv/mscep/mscep.dll
usage ike
usage ssl-server
usage ssl-client
serial-number none
ip-address none
subject-name CN=my,OU=it,O=ru
crl query ldap://192.168.1.2
revocation-check crl
auto-enroll
%PKI-6-CERTREJECT: Certificate enrollment request was rejected by Certificate Authority
the signature of the certificate cannot be verified 0x80096004(-2146869244)
c2900-universalk9-mz.SPA.152-4.M1.bin
, the certificate is received without problems. CA config on 881 is completely copied from a working 2811. Answer the question
In order to leave comments, you need to log in
that's how it always is. it was worth asking the question how I got to the bottom of the solution myself :)
I had to regenerate the rsa keys on the router
crypto key generate rsa modulus 1024 general-keys
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question