Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Windows 2008 CA server and auto-enrollment

Hi,

We are doing a rollout for a new WAN network for  a private company. We configured the VPN tunnels using certificates  and the certificates are issued by a WIndows 2008 server using SCEP.  The certificates are valid for a year , we tried to configure  a new certificate template with a longer time but the WIn2008 server started to act strange. ( Note that we had a lot of issues with the Window2008 CA server ).

We  configured auto-enrollment with the command ( auto-enroll 95 )  so are certificates should get refreshed within   95 % of his lifetime.The problem is that you can't test it  :-(

Does anybody have any experience with this ?  Is their way so you can test it ?

I already tried with the manipulating the time but this doesn't work . THe router runs a small timer which says how long the certificate is valid.

Any input is welcome. If needed I can send a part of the config by email

thx

wimdd

1 REPLY
Cisco Employee

Re: Windows 2008 CA server and auto-enrollment

wim,

I've done testing of this feature for a case I had a year back.

I was however using IOS as my CA.

FIrst thing to check on IOS is to see what timers for pki are started:

"show cry pki timer"

bsns-7606-1#sh cry pki timers
PKI Timers
|320d 4:32:18.636
   |320d 4:32:18.636  SHADOW cisco

Marcin

866
Views
0
Helpful
1
Replies