Add certificate enrollment objects
Add certificate enrollment objects to manage device trustpoints and enable secure certificate enrollment for Firewall Threat Defense devices.
-
Support multiple enrollment protocols, including SCEP, EST, ACME, Manual, and PKCS12 file import.
Use these objects to enable secure certificate management and device trustpoint enrollment. You must have Admin or Network Admin privileges to do this task.
Procedure
Step 1 | Open the Add Certificate Enrollment dialog:
| ||
Step 2 | Enter the Name. When enrollment is complete, this name is used as the trustpoint name on the managed devices with which it is associated. Click the CA Information tab, and then choose the Enrollment Type.
| ||
Step 3 | Skip Check for CA flag in basic constraints of the CA Certificate—Check this check box if you want to skip checking the basic constraints extension and the CA flag in a trustpoint certificate. | ||
Step 4 | Validation Usage—Choose from the options to validate the certificate during a VPN connection:
| ||
Step 5 | (Optional) Click the Certificate Parameters tab and specify the certificate contents. See Certificate Enrollment Object certificate parameters in certificate requests. This information is placed in the certificate and is readable by any party who receives the certificate from the router. | ||
Step 6 | (Optional) Click the Key tab and specify the Key information. See Certificate Enrollment Object key options. | ||
Step 7 | (Optional) Click the Revocation tab and specify the revocation options: See Certificate Enrollment Object revocation options. | ||
Step 8 | Allow Overrides of this object if desired. When you allow overrides in the PKCS12 certificate enrollment object, update thePassphrase for the certificate on the device where you override it. See Object overrides for a full description of object overrides. | ||
Step 9 | Click Save. |
What to do next
Associate and install the enrollment object on a device to create a trustpoint on that device.
