Cisco 7925G Administration Guide - Page 94

User Installed Certificate, To verify the MIC

Page 94 highlights

Configuring Network Profiles Chapter 4 Using the Cisco Unified Wireless IP Phone 7925G Web Pages To verify the MIC, the Manufacturing Root Certificate and Manufacturing Certificate Authority (CA) Certificate must be exported from a Cisco Unified Wireless IP Phone 7925G and installed on the Cisco ACS server. These two certificates are part of the trusted certificate chain used to verify the MIC by the Cisco ACS server. To verify the Cisco ACS certificate, a trusted subordinate certificate (if any) and root certificate (created from a CA) on the Cisco ACS server must be exported and installed on the phone. These certificate(s) are part of the trusted certificate chain used to verify the trust of the certificate from the ACS server. User Installed Certificate To use a user installed certificate, a Certificate Signing Request (CSR) must be generated on the phone, sent to the CA for approval, and the approved certificate installed on the Cisco Unified Wireless IP Phone 7925G. During EAP-TLS authentication, the ACS server needs to verify the trust of the phone and the phone needs to verify the trust of the ACS server. To verify the authenticity of the user installed certificate, a trusted subordinate certificate (if any) and root certificate from the CA that approved the user certificate must be installed on the Cisco ACS server. These certificate(s) are part of the trusted certificate chain used to verify the trust of the user installed certificate. To verify the Cisco ACS certificate, a trusted subordinate certificate (if any) and root certificate (created from a CA) on the Cisco ACS server must be exported and installed on the phone. These certificate(s) are part of the trusted certificate chain used to verify the trust of the certificate from the ACS server. To install authentication certificates for EAP-TLS, perform the tasks listed in Table 4-6: Table 4-6 Installing the Certificate for EAP-TLS Task From For more information, see... 1. Set the Cisco Unified Cisco Unified Wireless IP Phone 7925G Setting the Date and Time, page 4-19 Communications Manager date and web page time on the phone. 2. If using the Manufacturing Installed • Cisco Unified Wireless IP Phone Exporting and Installing the Certificates Certificate (MIC): 7925G web page on the ACS, page 4-19 a. Export the CA root certificate and manufacturing CA certificate. • Internet Explorer • Microsoft Certificate Services Exporting the CA Certificate from the ACS Using Microsoft Certificate Services, page 4-20 b. Install certificates on the Cisco ACS server and edit the trust list. c. Export the CA certificate from the ACS server and import it to the phone. 4-18 Cisco Unified Wireless IP Phone 7925G Administration Guide for Cisco Unified Communications Manager 7.0(1) OL-15984-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244

4-18
Cisco Unified Wireless IP Phone 7925G Administration Guide for Cisco Unified Communications Manager 7.0(1)
OL-15984-01
Chapter 4
Using the Cisco Unified Wireless IP Phone 7925G Web Pages
Configuring Network Profiles
To verify the MIC, the Manufacturing Root Certificate and Manufacturing Certificate Authority (CA)
Certificate must be exported from a Cisco Unified Wireless IP Phone 7925G and installed on the Cisco
ACS server. These two certificates are part of the trusted certificate chain used to verify the MIC by the
Cisco ACS server.
To verify the Cisco ACS certificate, a trusted subordinate certificate (if any) and root certificate (created
from a CA) on the Cisco ACS server must be exported and installed on the phone. These certificate(s)
are part of the trusted certificate chain used to verify the trust of the certificate from the ACS server.
User Installed Certificate
To use a user installed certificate, a Certificate Signing Request (CSR) must be generated on the phone,
sent to the CA for approval, and the approved certificate installed on the Cisco Unified Wireless IP
Phone 7925G.
During EAP-TLS authentication, the ACS server needs to verify the trust of the phone and the phone
needs to verify the trust of the ACS server.
To verify the authenticity of the user installed certificate, a trusted subordinate certificate (if any) and
root certificate from the CA that approved the user certificate must be installed on the Cisco ACS server.
These certificate(s) are part of the trusted certificate chain used to verify the trust of the user installed
certificate.
To verify the Cisco ACS certificate, a trusted subordinate certificate (if any) and root certificate (created
from a CA) on the Cisco ACS server must be exported and installed on the phone. These certificate(s)
are part of the trusted certificate chain used to verify the trust of the certificate from the ACS server.
To install authentication certificates for EAP-TLS, perform the tasks listed in
Table 4-6
:
Table 4-6
Installing the Certificate for EAP-TLS
Task
From
For more information, see...
1.
Set the Cisco Unified
Communications Manager date and
time on the phone.
Cisco Unified Wireless IP Phone 7925G
web page
Setting the Date and Time, page 4-19
2.
If using the Manufacturing Installed
Certificate (MIC):
a.
Export the CA root certificate
and manufacturing CA
certificate.
b.
Install certificates on the
Cisco ACS server and edit the
trust list.
c.
Export the CA certificate from
the ACS server and import it to
the phone.
Cisco Unified Wireless IP Phone
7925G web page
Internet Explorer
Microsoft Certificate Services
Exporting and Installing the Certificates
on the ACS, page 4-19
Exporting the CA Certificate from the
ACS Using Microsoft Certificate
Services, page 4-20