Add certificate enrollment objects

Add certificate enrollment objects to manage device trustpoints and enable secure certificate enrollment for Firewall Threat Defense devices.

  • Support multiple enrollment protocols, including SCEP, EST, ACME, Manual, and PKCS12 file import.

Use these objects to enable secure certificate management and device trustpoint enrollment. You must have Admin or Network Admin privileges to do this task.

Procedure


Step 1

Open the Add Certificate Enrollment dialog:

  • Directly from Object Management: In the Objects > PKI > Certificate Enrollment from the navigation pane, and click Add Certificate Enrollment.
  • While configuring a managed device: In the Devices > Certificates screen, choose Add > Add New Certificate and click (add icon) for the Certificate Enrollment field.

Step 2

Enter the Name. When enrollment is complete, this name is used as the trustpoint name on the managed devices with which it is associated. Click the CA Information tab, and then choose the Enrollment Type.

  • Self-Signed Certificate—The managed device, acting as a CA, generates its own self-signed root certificate. No other information is needed in this pane.

    Note

    When enrolling a self-signed certificate you must specify the Common Name (CN) in the certificate parameters.

  • EST—Enrollment over Secure Transport protocol. Specify the EST information. See EST enrollment configuration options in Certificate Enrollment Object.
  • SCEP—(Default) Simple Certificate Enrollment Protocol. Specify the SCEP information. See Certificate Enrollment Object SCEP options.
  • Manual
    • CA Only—Check this check box to create only the CA certificate from the selected CA. An identity certificate will not be created for this certificate.

      If you do not select this check box, a CA certificate is not mandatory. You can generate the CSR without having a CA certificate and obtain the identity certificate.

    • CA Certificate—Paste the CA certificate in the PEM format in the box. You can also obtain a CA certificate by copying it from another device.

      You can leave this box empty if you choose to generate a CSR without the CA certificate.

  • PKCS12 File—Import a PKCS12 file on a Firewall Threat Defense managed device that supports VPN connectivity. A PKCS#12, or PFX, file holds a server certificate, intermediate certificates, and a private key in one encrypted file. Enter the Passphrase value for decryption.
  • ACME—ACME protocol is an open and standardized protocol designed to automate the issuance, renewal, and management of SSL and TLS certificates. Management Center communicates with an ACME-enabled CA server and after domain validation, the ACME server issues an SSL or TLS certificate to the device. See Certificate enrollment object options for ACME certificates.

Step 3

Skip Check for CA flag in basic constraints of the CA Certificate—Check this check box if you want to skip checking the basic constraints extension and the CA flag in a trustpoint certificate.

Step 4

Validation Usage—Choose from the options to validate the certificate during a VPN connection:

  • IPsec Client—Validate an IPsec client certificate for a site-to-site VPN connection.

  • SSL Client—Validate an SSL client certificate during a remote access VPN connection attempt.

  • SSL Server—Select to validate an SSL server certificate, such as a Cisco Umbrella server certificate.

Step 5

(Optional) Click the Certificate Parameters tab and specify the certificate contents. See Certificate Enrollment Object certificate parameters in certificate requests.

This information is placed in the certificate and is readable by any party who receives the certificate from the router.

Step 6

(Optional) Click the Key tab and specify the Key information. See Certificate Enrollment Object key options.

Step 7

(Optional) Click the Revocation tab and specify the revocation options: See Certificate Enrollment Object revocation options.

Step 8

Allow Overrides of this object if desired.

When you allow overrides in the PKCS12 certificate enrollment object, update thePassphrase for the certificate on the device where you override it.

See Object overrides for a full description of object overrides.

Step 9

Click Save.


What to do next

Associate and install the enrollment object on a device to create a trustpoint on that device.