Configure Certificate Automation
CMP configuration includes you confirming the scope of compliance with the CMP protocols that you can deploy, based on the capabilities of the external CAs with which you work. The SBC offers significant and evolving compliance with this protocol.
Before configuring certificate automation:
- Establish the scope and timing you intend to implement for automated certificate management.
- Identify external CA servers with which you are implementing your deployment.
- Confirm that the system displays the Superuser mode.
- Enable the Certificate Management Protocol (CMP) entitlement.
- Optionally, on the system-config element, set secure-certificate-mode to enabled.
This feature establishes automation
within your certificate management process. You do this by establishing your
CMP-specific configuration and then applying it to existing infrastructure elements.
Configuration begins from the cmp branch, from which you can
access the following configuration elements:
- cmp-global-config
- cmp-server
- cmp-server-group
- cmp-profile
- tls-profile: Enter the name, configured in the applicable cmp-profile to the cmp-profile parameter of each applicable tls-profile.
Follow the steps below to access the cmp branch:
Configure each element according to your deployment, referring to the ensuing
task documentation.