Installation certificate of 2nd by the same CA.

Try to install a second certificate issued by the same CA. However, the new certificate replaces its predecessor.

Registration certificate original Config:

Crypto pki trustpoint ca.domain.null

Enrollment url http://ca.domain.null:80

use of ike

IP address no

fingerprints

name of the object c = CA, st = State, l = city, o = Company, ou = old-1, or old-2 =, cn =router.domain.null

crl revocation checking

interface Loopback0 source

rsakeypair router.domain.null 1024

automatic registration of 90 regenerate

Changes to the configuration of the registration certificate:

Crypto pki trustpoint ca.domain.null

name of the object c = CA, st = State, l = city, o = Company, or new-1 = or = new-2, cn =vpn - 1.router.domain.null,vpn - 1.router.domain.null = host name

rsakeypair vpn - 1.router.domain.null 1024

Note: Fields modified organizational unit (OU).

Note: Specified another common name (prefixed "vpn-1").

Note: Tried it with and without «hostname = vpn - 1.router.domain.null»

Note: Specified another pair of RSA keys.

Registration for the second (same CA) certificate:

Router (config) #crypto pki register ca.domain.null

%

Certificate registration % at the beginning...

% Create a challenge password. You will need to verbally provide this

password for the CA administrator to revoke your certificate.

For security reasons your password is not saved in the configuration.

Please take note of it.

Password:

Re-enter the password:

% Will include in the certificate subject name: c = CA, st is State, l = city, o = Company, OU = new-1, or is new-2, cn isvpn - 1.router.domain.null, name of host =vpn - 1.router.domain.null

% Will include the name of the subject in the certificate: router.domain.null

% Include the serial number of the router in the name of the topic? [Yes/No]: n

Request a certification authority certificate? [Yes/No]: y

% Certificate request to the certification authority

% The command 'show the crypto certificate PKI detailed ca.domain.null' display the fingerprint.

Note: The above statement shows "% will include the name of the subject in the certificate: router.domain.null.

Note: The new certificate is created with the same name as the original certificate and replace.

New certificate:

Router (config) #do sh crypto PKI

Certificate

Status: available

Certificate serial number (hex): 23

Certificate use: general use

Issuer:

CN = ca.domain.null

Object:

Name: router.domain.null

hostname = Router .domain .null

c = CA

St = State

l = city

o = Company

UO = new-1

UO = new-2

CN =vpn - 1.router.domain.null

host name =vpn - 1.router.domain.null

CRL Distribution points:

http://CA.domain.null/cgi-bin/pkiclient.exe?operation=GetCRL

Validity date:

start date: 14:10:41 this December 4, 2012

end date: 04:24:14 EDT July 15, 2013

renewal date: 22:16:52 EDT June 22, 2013

Trustpoints Associates: ca.domain.null

Note: The following remain the same when the new certificate is created, despite the entry of object name provided:

Object:

Name: router.domain.null

hostname = Router .domain .null

The original of the certificate is replaced with a new one and should not be found in the

"sh crypto pki certificate" exit.

Any ideas or solutions successfully install a second certificate issued by the same authority would be welcome.

Best regards

Mike

Mike,

(Hopefully) answer both of your questions.

You can have different trustpoints with the same certificate of the issuer, no need to use two different cases.

I actually wasn't 100% corrent in my previous intervention, trustpoints will also have associated reversal/shadow certs, so strictly speaking more than two.

IRT. IKEv1 and identity, we have limited options.

(1) auto (pick up method according to the type of connection)

(2) address - provide the IP address associated with a card crypto instsance (i.e. the source of the cryptographic packages).

(3) Hostname - hostname configured on the box. (FQDN)

(4) DN - chosen DN of the certificate

http://www.Cisco.com/en/us/docs/iOS-XML/iOS/security/A1/sec-CR-C4.html#GUID-D3C7A306-A689-4953-9146-D4F2F861C567

In addition, you can configure user-name of full domain as identity.

http://www.Cisco.com/en/us/docs/iOS-XML/iOS/security/S1/sec-CR-s1.html#GUID-E0956592-4754-4C48-9ACB-9AF58594E74D

As far as IKE goes, you can have as many certificates as you want of cases as much as you want (in MM3 and MM4 both sides of the negotion will agree on the use of certificates to authenticate to each other).

M.

Tags: Cisco Security

Similar Questions

  • I have a new Apple and made a Migration of Applications. data etc old Apple Apple again. Creative cloud gives error re damaged and to download and install again, however, after doing this installation starts but keeps giving the same error re C

    I have a new Apple and made a Migration of Applications. data etc old Apple Apple again. Creative cloud gives error re damaged and to download and install again, however, after doing this installation starts but keeps giving the same error re file creative cloud. How to solve?

    Uninstall, use the CS cleaning tool, and then reinstall.

    Adobe Creative Suite Cleaner Tool allows to solve the problems of installation for CS3 thru CS6 and creative cloud

    http://www.Adobe.com/support/contact/cscleanertool.html

  • Use certificate and form to the same application of ADF basic authentication

    Hello

    We have an application that needs to use time based authentication CLIENT-CERT and FORM.

    I have configured a domain with Client certificate requested and applied, generated a client certificate, created an Asserter custom identity with a Login Module and successfully recorded in our application using the CLIENT-CERT. , our customer wants to use the FORMS authentication at the same time with the CLIENT-CERT authentication type.

    The idea only I had was to use a servlet proxy deployed on another instance of WebLogic (10.3.6) that uses the CLIENT-CERT authentication that will forward requests to the main ADF application using classic FORM based authentication. The problem with this approach is that the proxy servlet is accessible using HTTPS and the communication between himself and the application of the ADF is made by using HTTP, so the client browser is redirected to HTTP on first access. For example, if I used Apache to proxy requests that would have been easily solved using RequestHeader set true WL-Proxy-SSL.

    You have any other suggestions on how to achieve this?


    Thank you in advance,


    Ionut Cristian Paraschiv

    Multichannel Solution Architect

    Advahoo Business Solutions

    I found a work around for this problem:

    -l'application uses FORMS authentication in function

    -l'application is deployed on a server managed with Client Cert has requested and applied (only clients with certificates will connect over HTTPS)

    -the login page has only one input for the password text

    -in the bean of login, in the doLogin() method page, we can get the certified client and get the username with a custom class of UserNameMapper

    Object certChain = request.getAttribute ("javax.servlet.request.X509Certificate");

    Certificate CERT [] = certChain (certificate []);

    X509Certificate cert = (X509Certificate) CERT [0];

    ... to get the user name

    Ionut Cristian Paraschiv

    Multichannel Solution Architect

    Advahoo Business Solutions

  • Installations of multiple Apex on the same server

    Hello

    We plan to spend some of the data in our Oracle database to another database on the same server.
    Now the problem is that there are a number of Apex applications that use these data.
    So I wonder if it is possible to create a second installation of Apex (and HTTP server?) on the same server, connect to the new database.

    We use the database with Oracle HTTP server and Apex 3.1.2 10.2.0.4.


    Thank you
    Matthias

    Hello

    a database can have only one installation of APEX active. But you can have several databases with an APEX in each database
    on the same server. You can even use the same HTTP server - you just neen an additional inscription of DADDY for the second database APEX
    in your dads.conf file, for example


    :
    Database configuration data 1
    :


    :
    Attributes for the second database here
    :

    Does that help?
    Carsten-

  • Can a genuine windows installation be legally installed on the same computer more than once

    I had the unconscious idea that a person can install windows as much as they want as long it is on the same computer and it has the same material, but it may be a different partition.  So I guess I can legally install MS Windows Vista, 7 or xp as many times as I want as long as it is on the same computer.  Maybe that's how integrators.

    Thank you.

    Hello

    Yes, you can install the same copy of windows on the same computer as many times as you want and activate for any number of times.

  • VShield service Manager installation and vShield app to the same host ESXi

    Hello, I'm planning on vCloud Director assessment in a laboratory with only a single ESXi host.  When I try to install the app vShield service I get the following warning: do not install on a host or a cluster where the VC or the vShield Manager resides. This can cause network problems. The following IP address must be a unique IP address assigned to this unit of App vShield. Please do not use an IP address that is assigned to another machine, including the VC, vShield Manager or any ESX host. Using an incorrect IP address you will need to uninstall and reinstall App vShield on this host. My question is: is it is absolutely impossible to install vShield manager on the same host ESXi as the vShield Manager resides?  Or is it just a bad practice?  What are the ramifications of installing?

    It is a general practice to separate management and resources. What you see is just a warning. When there are very fewer resources available you can do. Make sure that you exclude from the required VM by referring to this post

    http://www.yellow-bricks.com/2012/03/17/excluding-your-vCenter-server-from-VShield-app-protection/

  • can I save files with easy transfer before you perform a clean installation of Windows 7 on the same PC?

    I have an era of BIOS in Windows 7 and have to restart from the installation disc.  I want to save my files before doing a clean install to remove my problem then re - install my files after the slate.  Can I use Windows easy transfer to save the files, even on a partition on the drive C: then do 'clean' installation and subsequently transferring my files stored in Windows 7 on another partition, same computer?

    I could live in a dream world...
    Thank you
    Sam

    Yes, but it is strongly recommended to use an external storage for backup device.

    http://www.notebooks.com/2009/10/07/using-Windows-easy-transfer-in-Windows-7/

  • My iPod Shuffle 2nd Gen the same song just rehearsals

    I have an Ipod 2nd generation shuffle, and he will never play the song I put on, he would usually play about 6 of the continuously, despite having lots of songs on this subject. I recently restored to factory settings and got 64 songs on it, but he will play only one of them, which she repeats,

    The shuffle uses flash storage.  Flash storage ends by wears.  Thus, the cause may be a hardware problem on your shuffle, especially since a 2nd gen shuffle is about 10 years at this point.

    One thing you can try is to reformat the shuffle outside iTunes store.  This must be done in a particular way.  Are you using a Mac or a Windows PC?

  • Install 2 variants of the same prog

    Hi all

    I have a B project, from A project. They are both with the current development. As well in different directories, all the code is duplicated in each directories (and verified that it isn't all criss-cross). Projects and executables targets have different names.

    Now, I create a distribution for each. I install first of all B. Then I try to install the A on the same machine, but he refuses, saying that there is already a more recent version. It is not completely wrong, but because the names and directories (like target directories) are different, how is he believes that two installation programs are for the same program?

    In [settings target] version numbers are lower than for B, as it should.

    [Edit Installer] [general] the version number has the auto-increment value, and B is greater than one, but why should it matter if the names and output directories are different?

    If I install A, then B, a C:\Program Files\ disappears. Why is this?

    I grepped the .prj and .cds files and see no dir or target namespace in common.

    You can have problems from these two projects, sharing the same GUID (Globally Unique Identifier): this number is created when you set up a distribution, so if you happen to have copied the entire project to a different folder, including the .cds file, you encounter the same GUID for both projects. If this is true, for the installation program you really are installation of two copies of the same application and therefore you cannot get off it and install a more recent version will remove the previous.

    I never found myself in the same situation as you, but I guess that you can create a new GUID for a single application on your part by removing the .cds file and creating a new distribution, because the GUID is stored in the file .cds.

    Another solution may be to go to the general tab of your distributions, and then select the Side-by-Side.

    This is the guide for creating a distribution you will find also in aid of the CVI: it is the basic reference for studying the characteristics of the distribution.

  • ProBook 455 L3P93ES G2 #ABZ: installation without end and return the video driver AMD R6 and R7 M260DX and stop on a black screen system

    Hello, I'm in trouble with this problem. If anyone can help me, I appreciate a lot. Thank you in advance.

    Laptop: HP ProBook 455 G2 L3P93ES #ABZ

    Problem: windows back AMD R6 and R7 video driver to the old version of windows update install. Return process the screen come black and stop here.

    Procedure, I followed:

    1. updating the bios with the latest version (M75_0141.bin)
    2. new facility created by HP Cloud recovery customer USB boot disk
    3. Install the drivers and programs of the HPSoftwareSetup.exe util
    4. Connect the network cable and upgrade the drivers and the HP Support tool programs assistant
    5. Install the software
    6. Join the Organization's domain
    7. Force Windows Update to version 1607 by the upgrade of Windows tool
    8. Windows Update

    Item 4, at random, windows update 10 and return the driver from these versions:

    • 15.201.1301.0
    • 15.201.2301.0
    • 15.300.1025.1001

    I don't have install the AMD specific video driver (Radeon Crimson Edition 16.7.3 software) or drivers from the Chipset AMD (Crimson edition 16.7.3) because when I try in a previous installation of test I had the same problems

    To restore the display I have to start windows in safe mode and disable the two R6 and R7 display cards, and then restart. After that I can reactivate the cards one time.

    This device first question first time I install Windows 10 the year in August (Yes, after a few days Windows 10 out)

    Any help that will be much appreciate because I have to reinstall on 20 laptops for the school to start the day.

    Thank you

    ScuolaCarovana

    Hello;

    Let me welcome you on the HP forums!

    From your description, it seems that, after you have installed the correct video driver for your ProBook (15.201.1301) AMD, Windows Update is then by installing a different driver on top of that, right version?

    If this is the case, you must follow these instructions to STOP Windows update update drivers: how stop Windows 10 to update automatically the device drivers - windows Windows 10-10

    Once you do this, you should not see updates to the pilot after that.

    Good luck

  • I can't run in windows xp screen goes to normal boot options and mode safe but keeps coming back to the same screen

    I can't get windows xp to run - I set a restore point - rebooted - ann that he goes to the economy/regular mode promp but when I try to open windows it just brings back me to the same screen.  Tried to run the system restore but disc is not xrecognize it. Help!

    Thank you Gary

    Do not follow exactly...

    What is your system brand and model?

    What is your Version of XP and the Service Pack?

    Describe your current antivirus and software anti malware situation: McAfee, Symantec, Norton, Spybot, AVG, Avira!, MSE, Panda, Trend Micro, CA, Defender, ZoneAlarm, PC Tools, Comodo, etc..

    The question was preceded by a loss of power, aborted reboot or abnormal termination? (this includes the plug pulling, buttons power, remove the battery, etc.)

    The afflicted system has a CD/DVD drive work?

    You have a true bootable XP installation CD (it is not the same as any recovery CD provided with your system)?

    If your system uses to work properly, what do you think might have happened to her since the last time, that it did not work properly?

    If there is a problem starting, XP is configured to automatically try to start again and you can stuck in a loop not being able to go beyond the screen boot options, or none of these startup options you choose will work only.

    Sometimes, when XP has a problem starting or falls down and tries to start again, it will give you a "short" menu of boot options and none of them will appear to be good to get your system going again.  You have tried them all!

    The options are similar to the Advanced Boot Options menu XP, but the only option that you need (disable automatic error system reboot) are not offered, because XP went too far during the boot process and offers a limited number of boot options.

    If this is the case, you must call Options menu advanced boot yourself until you do not see the option:

    Disable the automatic restart in the event of system failure

    When you get the XP Advanced Options correct start menu you want to see, he has options on it like these:

    Safe mode
    Safe mode with networking
    Safe mode with command prompt

    Enable Boot logging
    Enable VGA mode
    Last good Configuration known (your most recent settings that worked)
    Directory Services Restore Mode (Windows domain controllers only)
    Debug mode
    Disable the automatic restart in the event of system failure

    Start Windows normally
    Reset
    Return to OS Choices Menu

    You need to choose in this menu is the option:

    Disable the automatic restart in the event of system failure

    Then if XP does not start normally, you will see an error screen with information and clues about the problem and then you can decide what to do next.

    If you do not see the automatic restart on system failure option turn it off, you must reset your system and start typing the key F8 on the keyboard until you see her disable automatic restart on system failure option.

    If you miss the window of opportunity F8, you must try again and start tapping the F8 key with more urgency (earlier and more frequently) until you see disable automatic restart on system failure, and then select.

    You must keep trying the F8 menu until you see disable automatic restart on system failure option, and select it.

    If your system has a Blue Screen of Death (BSOD), we need to know what the screen says:

    Here's a BSOD example showing information you provide:

    http://TechRepublic.com.com/i/tr/downloads/images/bsod_a.jpg

    Send for the nose and the Red arrows (3 to 4 lines total).

    Send all * line STOP message since there are clues in the 4 parameters.

    If it looks like there is some kind of name listed in the STOP message file, send this line also.

    Ignore the boring text unless it seems important to you.  We know what a BSOD looks like, we need to know what your BSOD looks like.

    Answering queries and results report of the disable automatic restart on system failure screen and you can decide what to do next.

  • Computer that has crushed - I have to reinstall the same operating system to avoid losing files.

    Basically, everything I've read about the BSOD "Unmountable boot error" I have tells me that I have to reinstall XP. The question is can I install a different operating system and not lose all my files on the computer? Thank you

    Hello

    ·        What is the exact error message that you encounter in Blue Screen of Death (BSOD)?

    ·        You are able to boot into safe mode without any problem?

    ·        Remember to make changes to the system?

    ·        Do you have the XP CD with you?

    Method 1:

    If you have the XP disc and then start in the recovery and then console perform a disk check. I suggest you to check the below link.

    When you restart your computer or upgrade to Windows XP, you receive the error message "STOP 0x000000ED UNMOUNTABLE_BOOT_VOLUME".

    http://support.Microsoft.com/?kbid=297185

    Method 2:

    If this does not help, then you can install a parallel installation of Windows XP on the same drive and then copy the important files and folders that are present on the system to an external device (flash drive), then install a new copy of the Windows XP operating system. Follow the steps mentioned in the article given below to perform a parallel installation of Windows XP.

    Follow method 4 that is listed in the article given below to perform a parallel installation of Windows XP.

    How to install or upgrade to Windows XP

    http://support.Microsoft.com/kb/978307

    Copy the files to an external device, and then create a clean install the operating system.

    I suggest you to check the links below, if you plan to install Windows Vista or Windows 7

    Install, reinstall, and then uninstall

    http://Windows.Microsoft.com/en-us/Windows/help/install-reinstall-uninstall

    Perform a custom installation of Windows 7

    http://Windows.Microsoft.com/en-us/Windows7/help/performing-custom-installation-Windows-7

    Thanks and regards.

    Thahaseena M
    Microsoft Answers Support Engineer.
    Visit our Microsoft answers feedback Forum and let us know what you think.

  • Can I install multiple copies of Vista Ultimate on the same machine?

    Hello

    I want to give to my family access to my machine (after a lot of introspection - us material are very protective of our stuff :)).  However, I will not give them access to my installation optimized for Vista game: it took an eternity of disabling and uninstalling things to do to get into this State.

    I know at least one of them will want to install full of things, such as the device drivers and IBM DB2 and other things that I don't really want to have it on my setup, that is purely for the start in as fast as possible and to play games on.

    So I want to install another copy of Vista on a different hard disk on the same computer to use.

    Will it be legal?  It will activate OK?

    Thank you

    Hello

    NO.

    It's not legal

    A vista license = AN installation of vista, even on the same computer

    You can set up different accounts for them in the existing vista installation

    User accounts to ensure that several people can easily share a single computer. Each person can have a separate user account with unique settings and preferences, such as a background theme and color office. User accounts also control the files and programs that you can access and what kinds of changes you can make to the computer. As a general rule, you'll want to create standard accounts for most computer users.

    http://Windows.Microsoft.com/en-us/Windows-Vista/create-a-user-account

  • How one properly installed more than one printer all-in-one (different) on the same pcr?

    Once installed 1 All in one printer, how one installs another printer all-in-one (different model) on the same computer without altering the first installation because all software are the same for each all-in-one printer, with the exception of different drivers linked to each different model all-in-one printer?

    Hello Boothkp,

    From what I can understand in your post, you are looking for a solution install several all in printers on one system, without causing problems during the first installation. This can be easy.

    Lets say you have 2 printer that both use the version 14 of the HP Solution Center software. Then, you install the first complete printer with all the software you want to use. The second installation, you just select the option 'Add printer' or 'Add features', this will add then the second printer in the current center solution without a conflict.

    In case this does not work, then please give more information on the model and the operating system you are working on.

    Kind regards

    Van Baardewijk

  • Is OSR taken 11.1.1.6 supported in the same field from SOA 11.1.1.7?

    Hello


    Can someone confirm if OSR 11.1. 1.6 is supported in the same field from SOA 11.1.1.7?

    Y at - it no document indicating 11.1.1.6 & one 11.1.1.7 can coexist in the same area.

    Thanks in advance,

    Vijaya

    Hi Vijaya,

    I suppose that there is nothing wrong with having the 11.1.1.6 SBA and SOA 11.1.1.7 as part of the same domain. These two products have the same supported version of i.e. of weblogic 11 GR 1 material WebLogic Server (+ 10.3.5).

    How ever, there are some prerequisites that we must follow when installing OSR 11 g in the area and the same as Oracle SOA Suite 11 g Weblogic environment.

    Here are some documents that will be useful

    (1) the prerequisites provided in the release notes for the respective operating system. This is how we do for IBM AIX

    http://docs.Oracle.com/CD/E28280_01/doc.1111/e14771/install.htm#ASRAX6165

    (2) support Note Doc ID 1089793.1: installation OSR 11 g in the same Weblogic environment and area that Oracle SOA Suite 11 g PS1 and PS2

    Requires the password and username of support Oracle

    OSR 11 g topology recommended

    Please let me know if this is useful.

    Best regards

    Amandine

Maybe you are looking for