Cisco 7921G Administration Guide - Page 92

Requesting and Importing the User Installed Certificate, DER encoded binary X.509 .CER, User Installed

Page 92 highlights

Configuring Network Profiles Chapter 4 Using the Cisco Unified Wireless IP Phone 7921G Web Pages To export the CA certificate using the Microsoft Certificate Services web page, follow these steps: Procedure Step 1 Step 2 Step 3 From the Microsoft Certificate Services web page, select Download a CA certificate, certificate chain or CRL. At the next page, highlight the current CA certificate in the text box, choose DER under Encoding Method, then click Download CA certificate. Save the CA certificate. Exporting Certificates from the ACS Server Using Internet Explorer Use this method for exporting the CA certificate from the ACS server that uses a self-signed certificate. To export certificates from the ACS server using Internet Explorer, follow these steps: Procedure Step 1 Step 2 Step 3 Step 4 Step 5 Step 6 From Internet Explorer, choose Tools > Internet Options, then click the Content tab. Under Certificates, click Certificates..., then click the Trusted Root Certification Authorities tab. Highlight the root certificate and click Export.... The Certificate Export Wizard appears. Click Next. At the next window, select DER encoded binary X.509 (.CER), and click Next. Specify a name for the certificate and click Next. Save the CA certificate to be installed on the phone. Requesting and Importing the User Installed Certificate To request and install the certificate on the phone, follow these steps: Procedure Step 1 Step 2 From the phone web page, choose the network profile using EAP-TLS, and select User Installed in the EAP-TLS Certificate field. Click Certificates. On the User Certificate Installation page, the Common Name field should match the user name in the ACS server. Note You can edit the Common Name field if you wish. Make sure that it matches the user name in the ACS server. See "Configuring the ACS Server Setup" section on page 4-23. Step 3 Enter the information to be displayed on the certificate, and click Submit to generate the Certificate Signing Request (CSR). In the next screen, select and copy the entire contents of the text box. Send this data to the CA administrator for signing. The CSR text is encoded and should be sent to the Certificate Authority for signing. The CSR text can be sent by e-mail or another method determined by your CA administrator. The following steps describe the basic CSR approval process on the CA web page. 4-22 Cisco Unified Wireless IP Phone 7921G Administration Guide for Cisco Unified Communications Manager Release 7.0 OL-15985-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234

4-22
Cisco Unified Wireless IP Phone 7921G Administration Guide for Cisco Unified Communications Manager Release 7.0
OL-15985-01
Chapter 4
Using the Cisco Unified Wireless IP Phone 7921G Web Pages
Configuring Network Profiles
To export the CA certificate using the Microsoft Certificate Services web page, follow these steps:
Procedure
Step 1
From the Microsoft Certificate Services web page, select Download a CA certificate, certificate chain
or CRL.
Step 2
At the next page, highlight the current CA certificate in the text box, choose DER under Encoding
Method, then click Download CA certificate.
Step 3
Save the CA certificate.
Exporting Certificates from the ACS Server Using Internet Explorer
Use this method for exporting the CA certificate from the ACS server that uses a self-signed certificate.
To export certificates from the ACS server using Internet Explorer, follow these steps:
Procedure
Step 1
From Internet Explorer, choose Tools > Internet Options, then click the Content tab.
Step 2
Under Certificates, click
Certificates...
, then click the Trusted Root Certification Authorities tab.
Step 3
Highlight the root certificate and click
Export...
. The Certificate Export Wizard appears. Click
Next
.
Step 4
At the next window, select
DER encoded binary X.509 (.CER)
, and click
Next
.
Step 5
Specify a name for the certificate and click
Next
.
Step 6
Save the CA certificate to be installed on the phone.
Requesting and Importing the User Installed Certificate
To request and install the certificate on the phone, follow these steps:
Procedure
Step 1
From the phone web page, choose the network profile using EAP-TLS, and select
User Installed
in the
EAP-TLS Certificate field.
Step 2
Click
Certificates
. On the User Certificate Installation page, the Common Name field should match the
user name in the ACS server.
Note
You can edit the Common Name field if you wish. Make sure that it matches the user name in
the ACS server. See
“Configuring the ACS Server Setup” section on page 4-23
.
Enter the information to be displayed on the certificate, and click
Submit
to generate the Certificate
Signing Request (CSR).
Step 3
In the next screen, select and copy the entire contents of the text box. Send this data to the CA
administrator for signing.
The CSR text is encoded and should be sent to the Certificate Authority for signing. The CSR text can
be sent by e-mail or another method determined by your CA administrator. The following steps describe
the basic CSR approval process on the CA web page.