Specifications

14-13
Cisco NAC Appliance - Clean Access Manager Configuration Guide
OL-28003-01
Chapter 14 Administering the CAM
Manage CAM SSL Certificates
Figure 14-6 Export CSR/Private Key
Step 2
Click Generate Certification Request to expose the fields required to construct a certificate request.
Step 3 Type appropriate values for the following fields:
Full Domain Name or IP—The fully qualified domain name or IP address of the Clean Access
Manager for which the certificate is to apply. For example:
camanager.<your_domain_name>
Organization Unit Name—The name of the unit within the organization, if applicable.
Organization Name—The legal name of the organization.
City Name—The city in which the organization is legally located.
State Name—The full name of the state in which the organization is legally located.
2-letter Country Code—The two-character, ISO-format country code, such as GB for Great Britain
or US for the United States.
Step 4 Specify whether you want the new temporary certificate to use a 1024-, 2048-, or 4096-bit RSA Key
Size.
Step 5 Click Generate to generate a certificate request. Make sure these are the ones for which you want to
submit the CSR to the certificate authority.
Step 6 Before you submit the new CSR to the Certificate Authority, save the new certification request and
Private Key used to generate the request to your local machine by enabling the checkboxes for the
Certification Request and/or Private Key and clicking Export. You are prompted to save or open the
file (see Default File Names for Exported Files, page 14-14). Save it to a secure location. Use the CSR
file to request a certificate from a certificate authority. When you order a certificate, you may be asked
to copy and paste the contents of the CSR file into a CSR field of the order form.
Alternatively, you can immediately Open the CSR in Wordpad or a similar text editor if you are ready
to fill out the certificate request form, but Cisco strongly recommends you also save a local copy of the
CSR and Private Key to ensure you have them should the request process suffer some sort of mishap or
your CAM basic configuration change between submitting the CSR and receiving your CA-signed
certificate.