How to generate CSR on switches for web auth with NGS

Hello

I do solution dot1x with web auth on switches cisco 3750.

Once the wired customer put in the web authentication status (after dot1x and mab) and goes to a website, he receives a certificate warning. This is because as the switch cisco selfsigned certificate.

I want to use a verisign certificate to resolve this error, but I can't find a way to generate a CSR on a switch. I only found a guide how to request a certificate from a CA on the local network, but it is also not a solution, because the customers with the help of web authentication, won't the internal certification authority.

Is it possible to fix this?

Greetings

Steven

Hi Steven,

The document below is really for IOS SSLVPN, but the part of the certificate must be the same:

http://www.Cisco.com/en/us/prod/collateral/iosswrel/ps6537/ps6586/ps6657/white_paper_c07-372106_ps6657_Products_White_Paper.html

Search for the 'Annex B' and it goes into the creation of a trustpoint and then a section for the self-signed and another is to generate a certificate request to send to an external certification authority.

Once created a trustpoint command to actually generate the CSR is "crypto PKI enroll."

This document goes into a bit more details on orders of the person and what they do:

http://www.Cisco.com/en/us/docs/iOS/sec_secure_connectivity/configuration/guide/sec_cert_enroll_pki.html

Also, you can use something external to the switch as OpenSSL to generate the CSR and private key and then use it to request a certificate from your Verisign CA and then import the cert/key pair in the IOS device.

Thank you

Nate

Tags: Cisco Security

Similar Questions

  • How to config a cache shared for several environments with the C API

    How to config a cache shared for several environments with C API?  Like Java edition. Chapter 2. Database environments

    I want to open the large number of databases, at least 10,000. But as the counties of open databases increase, the db-> open become very slow operation. It took almost 2 hours for 10 000 databases.

    So I try to distribute these databases on multiple environments (for example, 5 envs). And to improve the efficiency of memory use, I want to share cache between ENVS.

    Hello

    We do not support the cache sharing between different environments as you mentioned.

    We have tested the case of the opening of 100 000 databases, see the number that you have encountered, we will check what is happening.

    Kind regards

    Winter, Oracle Berkeley DB

  • How To Generate Debug Log Files for ebs jsp?

    Hi how to generate debug log for ebs r12 jsp files?
    and where I get the journal me .please help thank you!

    Please check following Document MOS

    Oracle Application Server diagnostic tools and logs in Applications, version 12 (Doc ID 454178.1)

  • How to generate reports in pdf for interfaces and packages

    Hello

    How to generate mappings of interface and package pdf reports. I'm currently using the odi11g version.

    Kind regards
    SH.

    Hi HS,.

    Develop your projectand right click on the project folder and click print, you will get options to choose from like packages, Interfaces... all you have to do is provide the destination path

    Kind regards
    M

  • 5508 loading cert for web auth

    I have web auth enabled on the WLC so when clients connect, they get a cert error because it uses a self signed cert.  I was reading upward on obtaining a third part cert and he tells have openssl and then generate the cert and send it to a third-party CA etc.

    All the links that you can share would be very useful, explaining best practices and to load a cert of third party on the WLC 5508 for web authentication.

    Why can't just get a cert from them for our domain and simply load on the WLC?

    Hi Mohammed,.

    Here are the two links that are like the bible to generate certificates...

    http://www.Cisco.com/en/us/products/ps6366/products_configuration_example09186a0080a77592.shtml

    http://www.Cisco.com/en/us/Tech/tk722/tk809/technologies_configuration_example09186a00806e367a.shtml

    Depends on whether you use Chained or chained UN CERT... Following the link above will help you to get the problem resolved!

    Let me know if this answers your question!

    Concerning

    Surendra

  • How can I go directly to a web site with output sorted by bing or google or any search engine. I want to go directly to this address

    When I type in a web address it gets filtered by bing and the web site I want is not displayed.

    How can we the a web address with it being sorted to be a search engine

    Not sure what you mean.  If I type in a web address and press 'Go', it takes me straight to this site.  The drop-down list that appears is the most popular hits that match what you type.

  • R12 - how to generate a unique Journal for several bills entry

    Hello

    We observed that in R12, when newspapers are transferred to GL SLA, separate Journal header is created for each invoice AP. This will affect huge negative performance on our existing custom programs.

    What we want is when we transfer reviews from AP to GL at end of day every day, so don't that a single Journal Header(like in 11i) generate for all bills.

    In addition, what we have observed is by default the name of the Journal header is in the following format

    "AE_HEADER_ID +" "+ purchase invoices + ' ' + SOBCurreny.

    Example of log name is «5250003 purchase invoices USD»

    We are not sure weather that a separate Journal header is created due to the default of naming convenstion. Is what is happening because, by default, the AE_HEADER_ID is in the name of the header of the Journal? If we modify the subledger accounting method and remove the AE_HEADER_ID the name of the entry of newspaper Oracle generates a signle Journal entry on all invoices?

    Please let me know if anyone has an idea on how to achieve this.


    Thank you
    Lokesh.

    In my view, the patch 8846459 solve the problem.
    Please cross check.

    By
    VAMSi

  • How can ad a special font for Web site?

    Hi all

    I want to incorporate a special font to embeded into my site, how can I do?

    Thank you

    Maury

    Here's a tutorial on embedding web fonts: http://www.smashingmagazine.com/2011/03/02/the-font-face-rule-revisited-and-useful-tricks/

    Here is a good site to find fonts: http://www.fontsquirrel.com

    If you have a font on your computer, this does not mean that you have the right to distribute or to host the font on your website.  If this isn't a web font then you would only be able to include special police in an image.

  • How to create a gradient halo for web "master page".

    In collaboration with PS CS5.5.

    I need to create a background image x 650px 1000px for a web application. I wish that the size of the resulting (PNG) file uploaded by the web site to be in the realm of 50 KB.

    What is the general strategy for the creation of a gradient as the attachment?

    Should I start with a solid background color and overlay the solid with a white gradient layer (Center being less transparent)... in my mind would result in the smallest size of file given I could decrease the resolution (of the exported PNG file) without any visible effect on the web page.

    Please advise,

    Bradbg.jpg

    There may be several ways to do it, but you could make a round radial gradient layer, adjust it to your liking, then save in PNG and just resize to any size you like in the HTML code, which might get you the oval shape.  Or you can rasterize in Photoshop and save it as a version of "crushed" to a small possible savings in file size.

    The gradient of 500 x 325 pixels above saved as a PNG image is about 50 KB.

    It has been cropped, pixelated and crushed vertically and takes only 26 kb on disk.

    -Christmas

  • How integrate you windows media player for Web sites?

    How do I can integrate my windows Media Player to another site that is not my home page so I can listen to my music, and others can listen too?

    Do some reading here

  • Draemweaver CS5.5; How to designate a remote server for web site folder

    Having a complete website built w / DW CS5.5 who I am trying to load on my GoDaddy hosting account. Site uploaded to the root directory of my GoDaddy account instead of the 'public_html' folder in the folder root. Want to re - download the 'public_html' folder, but there is no apparent provision in DW to point the upload to a specific folder (i.e., public_html) in the root directory of my account.

    On my GoDaddy website management page, I can spend my file root GoDaddy files downloaded in the public_html folder subordinate, but have to make an image file/t once (against a folder of files). It's a ton of shots, but more importantly, moving them individually will break all the links, so is not an option.

    Any ideas how to target the "public_html" folder in my folder root so I can re - download site here?

    Site > new Site or manage Sites.  See screenshots.

    Servers: In your case, the root directory is public_html / htdocs not.

    You should NEVER see the root directory in your local files Panel.  If you see in the local files Panel, your site is not properly set and you probably duplicated this folder on your server.

    Nancy O.

  • How to generate the serial number for the lines of the form. PLEASE HELP GUYS

    I have a tabular presentation. in which I have a column named Serial_number. I want to change the line (by enter or click the mouse) shape is expected to generate automatically in the next serial number.

    Published by: Gul on March 9, 2012 16:09

    Dear Gul

    Create a trigger a TIMES-NEWS-RECORD-INSTANCE at the block level.
    &
    Write the code in the following trigger

    IF: SYSTEM. RECORD_STATUS = 'NEW' THEN
    *: + YOUR_BLOCK_NAME +. SERIAL_NUMBER: =: SYSTEM. CURSOR_RECORD; *
    END IF;

    Hope this can solve your problem.

  • How to create a menu burger for mobile devices with submenus?

    Hello

    I don't understand why Muse have still a self building mobile menu as it does for Desktop - Web sites. All other tools like RapidWeaver done!

    So I have to build my own burger menu manually. The problem is: How can I build with the submenus? Levels got more complex Web site and it would be much better, if the user can access directly through each of them on a mobile device in a burger menu.

    Can anyone help?

    I don't see what you want potential problems.

    Not 100% what you want, but the simple option is to nest panels in accordion inside each other. I spent 10 minutes during lunch at one place scheme (the burger is bad image and size of items is all wrong, but you can play with it (and change from pretty bad looking for something OK/good)).

    Mock up quick hamburger

    If you really want a slide from the right as in the example you have pointed out, you need to insert some html/css:

    -build the submenu just next to the page and the group. Listen to samples and inspect the element chromium to find the UID of the group. The click of the menu item, call the submenu UID and move the element on the page. Include the ease settings to soften the transition.

    Can go more in detail if you wish.

    Good luck and sorry is not the prettiest workaround. Maybe build widget a day.

  • How is it difficult to update a Web site with mobile platforms, but also office?

    I just updated my CC from Adobe for photographers to the full version of CC for most to get Muse. I thought it was completely adaptable to mobile devices. Now I find that that is not necessarily true. It is true that I have to run three different platforms for mobile comparability? If this is true can I update all three, each time I change or add to my Web site? How is it hard to do this?

    Also, I read somewhere that if it is not hosted at Adobe, some of the Add-ons like forms and articles may not work. Is this correct?

    Thanks for any help,

    Linda

    Cross-platform support depends on what models / themes you use and their associated CSS and widgets. Not everything works everywhere and it is something you have to live with, has been for example support for JavaScript on mobile devices is usually a pain in the rear. Otherwise you get what you pay for - if you need more forms or other items, you will need to spend your limited options included in MU and look around. But I really don't see the issue. You can have anything from blogs to forums for free these days, you might just live with the fact that then you would not at all use Muse to manage and add content.

    Mylenium

  • How can I get a username for my account with my phone number?

    Sign in to Skype by using my cell phone number

    In fact, I signed up with my cell phone number

    People want to find me forced to search using my full name which may be similar to others, it's something not unique

    How can I get a unique username, so looking for people for me to use it and you identify with it?

    Thanks in advance,

    Concerning

    NoEscape wrote:

    How can I make a unique username?

    It is no longer possible.

    https://community.Skype.com/T5/account-setup-maintenance/changes-to-creating-a-new-Skype-account/TD-...

Maybe you are looking for

  • Need my reinstalled operating system

    My HP Pavilion p6610f harddrive failed.  I bought a new hard drive and installed in the computer.  Now, I have to get the operating system reinstalled.  I have my keycode os but don't know how to get the operating system.  This is my first attempt at

  • Go s5610y Pavilion Slimline: does not light

    When I press the power switch, the computer goes to the start screen then turns off and will not turn back on until I have unplug the power cord. Then it just does the same thing again

  • Dell XPS M1530 - Bluetooth 355 and Windows 7

    I just installed Windows 7 on my M1530, and everything works perfectly... EXCEPT bluetooth.  I downloaded the drivers from the website of dell (for 32-bit vista), but when I try to install it says "press Fn + F2 or turn on the wireless switch.  The w

  • cant for the update to win 10 after back to 7

    Im having (as far as I can find) corruption of the registry issues such as the "fix" tool said as much I had windows 10 upgrade and yet my little cousin has seen fit to return me back to 7 pro and whenever I try to get 10 back I have problems, includ

  • Need info on the IOS for 4503

    Hello We run a cisco 4503 with bootflash:cat4000 - i5s - mz.122 - 20.EW4.bin IOS on it, we are informed to upgrade the IOS on that. However, no info on what IOS must be deployed on that. Therefore, a certain to please you will suggest later IOS and u