Skip to content

SCEP provisioner for enrollment with Cisco routers #1289

Answered by hslatman
pedroaston asked this question in Q&A
Discussion options

You must be logged in to vote

Hey @pedroaston, am I correct you were using the CA generated by default before you tried enabling SCEP? If so, you'll need to create a new intermediate (at least the intermediate; it can be signed by the root that was generated before) for an RSA private key. Our SCEP configuration requires an RSA key, as the SCEP protocol relies on encryption against the CA public key. We have some documentation on how to configure the SCEP provisioner here: https://smallstep.com/docs/step-ca/provisioners#scep. Reconfiguring your CA to use an RSA certificate chain is described here: https://smallstep.com/docs/tutorials/rsa-chain.

If you did follow these instructions before, then it might be the case tha…

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
2 replies
@pedroaston
Comment options

@hslatman
Comment options

Answer selected by pedroaston
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants