Uploaded image for project: 'EJBCA'
  1. EJBCA
  2. ECA-9232

Document how to update the truststore (EST protocol)

    Details

    • Type: Task
    • Status: Closed
    • Priority: Minor
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: EJBCA 7.4.0
    • Component/s: None
    • Labels:
    • Issue discovered during:
      Customer
    • Sprint:
      EJBCA Team Alice - 2020 w23

      Description

      we are trying to enroll client certificates for Cisco IOS routers via EST protocol. We use RAs connected with SubCAs cluster via PeerConnect, so all the EST requests are proxied via RA to SubCA. On SubCA cluster we created dedicated EST CA for issuing these client certificates.

      We tested this concept and everything is working fine, except one thing. EST runs over TLS. The protocol needs to authenticate the client before allowing an enrollment request. So we were forced to import the whole chain of trust (Root CA, SubCA certificates) to router.

      On router there are SUDI certificates issued by Cisco (Public Root CAs). We want to use these certificates to create the initial TLS connection for EST enrollment. How can we add the certificates from Cisco CAs to be trusted by our PKI SubCAs and RAs

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              bastianf Bastian Fredriksson
              Reporter:
              younesj Younes Javan Chari
              Verified by:
              Mike Agrenius Kushner
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved:

                  Time Tracking

                  Estimated:
                  Original Estimate - 2 hours
                  2h
                  Remaining:
                  Time Spent - 45 minutes Remaining Estimate - 1 hour, 15 minutes
                  1h 15m
                  Logged:
                  Time Spent - 45 minutes Remaining Estimate - 1 hour, 15 minutes
                  45m