06-06-2014 01:18 PM
Hi,
I am trying to configure PKI on our new ASR1002-X routers. They are running advipservices IOS-XE 3.10s.
When trying to configure the PKI CA the crypto pki server command is not there. Also the sctp configuration option under ipc / associaction1 seem to be missing.
VPN-ASR1002-1#sh ver
Cisco IOS XE Software, Version 03.10.02.S - Extended Support Release
Cisco IOS Software, ASR1000 Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 15.3(3)S2, RELEASE SOFTWARE (fc3)
VPN-ASR1002-2(config)#crypto pki ?
authenticate Get the CA certificate
certificate Actions on certificates
crl Actions on certificate revocation lists
enroll Request a certificate from a CA
export Export certificate or PKCS12 file
import Import certificate or PKCS12 file
profile Define a certificate profile
token Configure cryptographic token
trustpoint Define a CA trustpoint
trustpool Define CA trustpool
I am missing something here?
Regards
Thomas
06-07-2014 12:28 AM
Thomas,
This code was never ported to IOS XE.
https://tools.cisco.com/bugsearch/bug/CSCul30163/?reffering_site=dumpcr
M.
08-04-2014 03:58 AM
Hi Marcin
I notice the bug has a fixed release of 15.5(0.13)S.
Can you confirm?
Our new hubs are 1002-x and we were planning to use the IOS PKI Server rather than mess with the Microsoft one.
Would prefer not to have to deploy a pair of ISR's for this.
08-11-2014 01:11 AM
The pre-commits are done (dated early July) and it looks like the code exists, but I do not see commits done. Or it could be a problem with the tools.
Possibly waiting for commit window, best to check with SE about the roadmap.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: