Configuring the sub-CA

The following section describes how to set up a sub-CA on a WLC. These steps assume that the device has been reset, that you have commissioned the device in the standard manner, and that you have set the correct time.

  1. Login to your device via WEBconfig or the command line.
  2. Navigate to the menu Setup > Certificates > SCEP-CA and set the parameter Root-CA to No.
  3. Navigate to the menu Setup > Certificates > SCEP-CA > CA-Certificates. Customize the name of the certificate authority (CA) and the registration authority (RA) with the parameters CA-Distinguished-Name and RA-Distinguished-Name.

    Example: /CN=WLC-SUB CA/O=LANCOM SYSTEMS/C=DE

  4. Switch to the menu Setup > Certificates > SCEP-CA > Sub-CA and enter the distinguished name of the root-CA under the parameter CADN.

    Example: /CN=WLC-MAIN CA/O=LANCOM SYSTEMS/C=DE

  5. For the parameter Challenge-Pwd , enter the challenge password that is stored on WLC-MAIN under Setup > Certificates > SCEP-CA.
  6. Enter the URL (address) to the root CA in the CA-Url-address parameter.
    If another WLC with the LCOS operating system provides the root CA, all you need to do is replace the IP address in the default value with the address where the corresponding device is to be reached. Example: http://192.168.1.1/cgi-bin/pkiclient.exe.
  7. Optional: Specify the Ext-Key-Usage and Cert-Key Usage to restrict the functions of the sub-CA. For more information, see the Menu Reference Guide.
  8. Set the parameter Auto-generated-request to Yes to activate the sub-CA.
  9. Navigate to the menu Setup > Certificates > SCEP-CA and set the parameter Operating to Yes to enable the CA server with SCEP.

You have now completed the configuration of the sub-CA. The command show ca cert on the command line allows you to verify that the WLC has created the certificate correctly. The hierarchy of certificates must be visible here: The WLC first displays the certificate of the root CA and then the certificate of the sub-CA.

www.lancom-systems.com

LANCOM Systems GmbH | A Rohde & Schwarz Company | Adenauerstr. 20/B2 | 52146 Wuerselen | Germany | E‑Mail info@lancom.de

LANCOM Logo