Cisco CA using 12.3T - R3 is CA, R4 is CA client

version 12.3
!
hostname r3

clock timezone EST -5
clock summer-time EST recurring

crypto pki server ca-cisco
issuer-name CN=ca-cisco.test.com L=New York C=US
grant auto
lifetime crl 72
lifetime ca-certificate 730
!
crypto pki trustpoint ca-cisco
revocation-check crl
rsakeypair ca-cisco
!
!
crypto pki certificate chain ca-cisco
certificate ca 01
30820231 3082019A A0030201 02020101 300D0609 2A864886 F70D0101 04050030
2C312A30 28060355 04031321 63612D63 6973636F 2E746573 742E636F 6D204C3D
4E657720 596F726B 20433D55 53301E17 0D303530 36313530 36323732 395A170D
30373036 31353036 32373239 5A302C31 2A302806 03550403 13216361 2D636973
636F2E74 6573742E 636F6D20 4C3D4E65 7720596F 726B2043 3D555330 819F300D
06092A86 4886F70D 01010105 0003818D 00308189 02818100 B2FA79AB 25B164A7
37EE0FD8 62877D5F E358B59E 651700A8 C5BFF345 6442E453 DC4A4B30 C4B13B26
B7161370 F857D3BF 2AAA15C6 8C311A9B 4E4F5085 AE2EEDFB 5E973EE7 CF57EAB5
50586F40 7E2B7655 F640129D FBD4AFC2 DB45C967 F8958B9E B4364E9B E008FEDB
CE2B9C1C 86945A26 08CE8D8D C8FE9B75 6FAFDDFC B86D5F87 02030100 01A36330
61300F06 03551D13 0101FF04 05300301 01FF300E 0603551D 0F0101FF 04040302
0186301F 0603551D 23041830 16801479 A7906AA6 C07609D5 E41F4407 80DFC3BA
C94C6F30 1D060355 1D0E0416 041479A7 906AA6C0 7609D5E4 1F440780 DFC3BAC9
4C6F300D 06092A86 4886F70D 01010405 00038181 00511252 6CD73988 B4CD10B3
BD15943D 80A1A9EF F51C2A11 D6C628DA 48F33D8A 8CE7B0A9 96703E81 4B406C8E
960CA053 8064EA33 426F3600 92EF8533 13DA7757 51B2E629 BBF420EC B24DAAB5
3DEB95AD 20125132 E689D700 694943C7 0F85EFC0 CAEF33FB 184D9463 90184D70
B365C163 6417AF24 23393198 2DECE209 D81FEA13 3D
quit
!
interface FastEthernet0/0
ip address 172.29.6.33 255.255.255.0

ip http server

r3#sh crypto ca certificate
CA Certificate
Status: Available
Certificate Serial Number: 01
Certificate Usage: Signature
Issuer:
cn=ca-cisco.test.com L/=New York C/=US
Subject:
cn=ca-cisco.test.com L/=New York C/=US
Validity Date:
start date: 02:27:29 EST Jun 15 2005
end date: 02:27:29 EST Jun 15 2007
Associated Trustpoints: ca-cisco


r3#sh crypto key mypubkey rsa
% Key pair was generated at: 03:40:52 EST Mar 1 2002
Key name: ca-cisco
Usage: General Purpose Key
Key is not exportable.
Key Data:
30819F30 0D06092A 864886F7 0D010101 05000381 8D003081 89028181 00B2FA79
AB25B164 A737EE0F D862877D 5FE358B5 9E651700 A8C5BFF3 456442E4 53DC4A4B
30C4B13B 26B71613 70F857D3 BF2AAA15 C68C311A 9B4E4F50 85AE2EED FB5E973E
E7CF57EA B550586F 407E2B76 55F64012 9DFBD4AF C2DB45C9 67F8958B 9EB4364E
9BE008FE DBCE2B9C 1C86945A 2608CE8D 8DC8FE9B 756FAFDD FCB86D5F 87020301 0001
% Key pair was generated at: 02:27:03 EST Jun 15 2005
Key name: test
Usage: General Purpose Key
Key is exportable.
Key Data:
305C300D 06092A86 4886F70D 01010105 00034B00 30480241 00F1CE58 09630EA6
C7BB16E1 824DF335 6EB3B21E DA272F9B D285C5B6 C0666E59 3E6BA9B7 E2A960CF
8C5D10A2 ACEE7731 7ECCC521 83BF0CE7 184AC8DF 43F0E340 75020301 0001
% Key pair was generated at: 03:27:13 EST Jun 15 2005
Key name: test.server
Usage: Encryption Key
Key is not exportable.
Key Data:
307C300D 06092A86 4886F70D 01010105 00036B00 30680261 00A13C7B 0FF115ED
38022E05 36482047 480A9185 EEEE82C8 2F9C3195 C1352C43 2396A0B2 868D0D69
D4BDDE9F 90458B38 A3E14A87 CBF105DE 97A22064 F6383C9D 8B222DCA DCC50364
39254684 8CF6720B 1CC80FC3 E97C5EDB A106C925 3A0AE6E7 F7020301 0001
r3#sh crypto pki server
Certificate Server ca-cisco:
Status: enabled
Server's configuration is locked (enter "shut" to unlock it)
Issuer name: CN=ca-cisco.test.com L=New York C=US
CA cert fingerprint: 51F6FF43 0F8BC55F A6C00179 4DF9B0C9
Granting mode is: auto
Last certificate issued serial number: 0x2
CA certificate expiration timer: 02:27:29 EST Jun 15 2007
CRL NextUpdate timer: 02:27:39 EST Jun 18 2005
Current storage dir: nvram:
Database Level: Minimum - no cert data written to storage
r3#sh crypto pki ?
certificates Show certificates
crls Show Certificate Revocation Lists
server Show Certificate Server
timers Show PKI Timers
trustpoints Show trustpoints

r3#sh crypto pki certificate
CA Certificate
Status: Available
Certificate Serial Number: 01
Certificate Usage: Signature
Issuer:
cn=ca-cisco.test.com L/=New York C/=US
Subject:
cn=ca-cisco.test.com L/=New York C/=US
Validity Date:
start date: 02:27:29 EST Jun 15 2005
end date: 02:27:29 EST Jun 15 2007
Associated Trustpoints: ca-cisco

==========================================
hostname r4

clock timezone EST -5
clock summer-time EST recurring

ip domain name test.com
!
crypto ca trustpoint test
enrollment url http://172.29.6.33:80
serial-number
!
crypto ca certificate chain test
certificate 03
308201DA 30820143 A0030201 02020103 300D0609 2A864886 F70D0101 04050030
2C312A30 28060355 04031321 63612D63 6973636F 2E746573 742E636F 6D204C3D
4E657720 596F726B 20433D55 53301E17 0D303530 36313531 33353630 365A170D
30363036 31353133 35363036 5A302D31 2B300F06 03550405 13083137 37343538
39333018 06092A86 4886F70D 01090216 0B72342E 74657374 2E636F6D 305C300D
06092A86 4886F70D 01010105 00034B00 30480241 00C6327D 90821BAE 0A88F1CE
B7A61FFA 1D7FEC4F F1EDEF0A 4EA8CA1B 542F7DD7 FBADF449 B1868B6F 340CEFC5
83B02137 CE4F6656 4EB58ABA CD6EFFE0 FE154E42 99020301 0001A34F 304D300B
0603551D 0F040403 0205A030 1F060355 1D230418 30168014 79A7906A A6C07609
D5E41F44 0780DFC3 BAC94C6F 301D0603 551D0E04 1604142C FBDE78B9 83DFC15D
6000F2C7 FEE8F419 9654B930 0D06092A 864886F7 0D010104 05000381 81002CB2
4C918EB1 0EEDF31A D334BDC9 972DE77E B00FC327 C5F03CD5 CCA0B141 CA782380
481E8A30 528E989B 73433CB5 6AC5F8A8 19CBF0CC 22031964 7E4A11B5 B5AEF502
CCA5A3CF 7BCDF390 F1393373 B6DC09B1 B093901C ED5E1FFE 2E61A689 F01CA278
9FF1EC49 F1DC7202 D5B53AB0 C972AB66 97D7D6B3 391BB034 BABBA3AC 1A1F
quit
certificate ca 01
30820231 3082019A A0030201 02020101 300D0609 2A864886 F70D0101 04050030
2C312A30 28060355 04031321 63612D63 6973636F 2E746573 742E636F 6D204C3D
4E657720 596F726B 20433D55 53301E17 0D303530 36313530 36323732 395A170D
30373036 31353036 32373239 5A302C31 2A302806 03550403 13216361 2D636973
636F2E74 6573742E 636F6D20 4C3D4E65 7720596F 726B2043 3D555330 819F300D
06092A86 4886F70D 01010105 0003818D 00308189 02818100 B2FA79AB 25B164A7
37EE0FD8 62877D5F E358B59E 651700A8 C5BFF345 6442E453 DC4A4B30 C4B13B26
B7161370 F857D3BF 2AAA15C6 8C311A9B 4E4F5085 AE2EEDFB 5E973EE7 CF57EAB5
50586F40 7E2B7655 F640129D FBD4AFC2 DB45C967 F8958B9E B4364E9B E008FEDB
CE2B9C1C 86945A26 08CE8D8D C8FE9B75 6FAFDDFC B86D5F87 02030100 01A36330
61300F06 03551D13 0101FF04 05300301 01FF300E 0603551D 0F0101FF 04040302
0186301F 0603551D 23041830 16801479 A7906AA6 C07609D5 E41F4407 80DFC3BA
C94C6F30 1D060355 1D0E0416 041479A7 906AA6C0 7609D5E4 1F440780 DFC3BAC9
4C6F300D 06092A86 4886F70D 01010405 00038181 00511252 6CD73988 B4CD10B3
BD15943D 80A1A9EF F51C2A11 D6C628DA 48F33D8A 8CE7B0A9 96703E81 4B406C8E
960CA053 8064EA33 426F3600 92EF8533 13DA7757 51B2E629 BBF420EC B24DAAB5
3DEB95AD 20125132 E689D700 694943C7 0F85EFC0 CAEF33FB 184D9463 90184D70
B365C163 6417AF24 23393198 2DECE209 D81FEA13 3D
quit
!
interface Ethernet0/0
ip address 172.29.6.34 255.255.255.0

r4# sh crypto ca certificate
Certificate
Status: Available
Certificate Serial Number: 03
Certificate Usage: General Purpose
Issuer:
cn=ca-cisco.test.com L/=New York C/=US
Subject:
Name: r4.test.com
Serial Number: 17745893
serialNumber=17745893+hostname=r4.test.com
Validity Date:
start date: 09:56:06 EST Jun 15 2005
end date: 09:56:06 EST Jun 15 2006
Associated Trustpoints: test

CA Certificate
Status: Available
Certificate Serial Number: 01
Certificate Usage: Signature
Issuer:
cn=ca-cisco.test.com L/=New York C/=US
Subject:
cn=ca-cisco.test.com L/=New York C/=US
Validity Date:
start date: 02:27:29 EST Jun 15 2005
end date: 02:27:29 EST Jun 15 2007
Associated Trustpoints: test  
  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值