Cisco NAC3350-PROF-K9 Hardware Installation Guide - Page 87

Important Notes for SSL Certificates, For further details on the CAM

Page 87 highlights

Chapter 3 Installing the Clean Access Manager and Clean Access Server Installing the Clean Access Manager Step 14 To log out of the web console, either click the administrator session Logout button, at the top right-hand corner of the console, or simply close the browser. Important Notes for SSL Certificates 1. You must generate the temporary SSL certificate during CAM installation or you will not be able to access your CAM as an end user. 2. After CAM and CAS installation, make sure to synchronize the time on the CAM and CAS via the web console interface before regenerating a temporary certificate on which a Certificate Signing Request (CSR) will be based. 3. In order to establish the initial secure communication channel between a CAM and CAS, you must import the root certificate from each appliance into the other appliance's trusted store so that the CAM can trust the CAS's certificate and vice-versa. 4. Before deploying the CAM in a production environment, Cisco strongly recommends acquiring a trusted certificate from a third-party Certificate Authority to replace the temporary certificate (in order to avoid the security warning that is displayed to the web user during admin login). For further details on the CAM, see the "Set System Time" and "Manage CAM SSL Certificates" sections of the Cisco NAC Appliance - Clean Access Manager Configuration Guide, Release 4.8(3). For details on the CAS, see the Cisco NAC Appliance - Clean Access Server Configuration Guide, Release 4.8(3). Note If your previous deployment uses a chain of SSL certificates that is incomplete, incorrect, or out of order, CAM/CAS communication may fail after upgrade to release 4.8(x). You must correct your certificate chain to successfully upgrade to release 4.8(x). For details on how to fix certificate errors on the CAM/CAS after upgrade to release 4.8(x), refer to the How to Fix Certificate Errors on the CAM/CAS After Upgrade Troubleshooting Tech Note. OL-20326-01 Cisco NAC Appliance Hardware Installation Guide 3-17

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176

3-17
Cisco NAC Appliance Hardware Installation Guide
OL-20326-01
Chapter 3
Installing the Clean Access Manager and Clean Access Server
Installing the Clean Access Manager
Step 14
To log out of the web console, either click the administrator session
Logout
button, at the top right-hand
corner of the console, or simply close the browser.
Important Notes for SSL Certificates
1.
You must generate the temporary SSL certificate during CAM installation or you will not be able to
access your CAM as an end user.
2.
After CAM and CAS installation, make sure to synchronize the time on the CAM and CAS via the
web console interface before regenerating a temporary certificate on which a Certificate Signing
Request (CSR) will be based.
3.
In order to establish the initial secure communication channel between a CAM and CAS, you must
import the root certificate from each appliance into the other appliance’s trusted store so that the
CAM can trust the CAS’s certificate and vice-versa.
4.
Before deploying the CAM in a production environment, Cisco strongly recommends acquiring a
trusted certificate from a third-party Certificate Authority to replace the temporary certificate (in
order to avoid the security warning that is displayed to the web user during admin login).
For further details on the CAM, see the “Set System Time” and “Manage CAM SSL Certificates”
sections of the
Cisco NAC Appliance - Clean Access Manager Configuration Guide, Release 4.8(3)
. For
details on the CAS, see the
Cisco NAC Appliance - Clean Access Server Configuration Guide, Release
4.8(3)
.
Note
If your previous deployment uses a chain of SSL certificates that is incomplete, incorrect, or out of order,
CAM/CAS communication may fail after upgrade to release 4.8(x). You must correct your certificate
chain to successfully upgrade to release 4.8(x). For details on how to fix certificate errors on the
CAM/CAS after upgrade to release 4.8(x), refer to the
How to Fix Certificate Errors on the CAM/CAS
After Upgrade
Troubleshooting Tech Note.