User`s guide

419
The following parameters allow the user to create a certificate request, enroll them and to
install the certificates on the router.
SCEP Server IP address
The IP address of the SCEP server / CA server.
Port
The port on which SCEP server is listening. If the port is 0, the default port of 80 will be
used.
Path
The path on the server to the SCEP application. You can either enter your own path or select
from cgi-bin or Microsoft SCEP from the drop-down list.
Application
The SCEP application running on the server.
CA identifier
The identifier for the CA server. The CA identifier to use to identify a particular CA when
multiple CAs might be running on the server.
CA certificate
The filename of the CA certificate.
CA encryption certificate
Sometimes when you get a CA certificate, a CA encryption certificate is installed on the router at
the same time. You can identify a CA encryption certificate by looking at the X.509 Key Usage
section in the certificate. It should say something like the following
X509v3 Key Usage: critical
Key Encipherment, Data Encipherment
If a CA encryption certificate has been installed by the CA you wish to use for the certificate
request, the CA encryption certificate should be entered.
If no CA encryption certificate has been installed for the CA, leave this file blank.
CA signature certificate
Sometimes when you get a CA certificate, a CA signature certificate is installed on the router at
the same time. You can identify a CA signature certificate by looking at the X.509 Key Usage
section in the certificate. It should say something like the following
X509v3 Key Usage: critical
Digital Signature, Non Repudiation
If a CA signature certificate has been installed by the CA you wish to use for the certificate
request, the CA signature certificate should be entered.
If no CA signature certificate has been installed for the CA, leave this file blank.
RSA Private key
This parameter allows you to select between using an existing private key and generating a
one for each certificate request.
Private key filename
The filename of the private key file to use.
Enrolment Password