Entrust Datacard

Entrust Certificate Services Support Knowledge Base

Last Modified: 2017-08-16 14:13:01.0

Entrust Datacard SSL/TLS certificate Installation Instructions: Cisco ACS version 5.x series

Article Number: 46528

User-added image

Before you begin...

  • Never share private keys files. 
  • If you plan on using the same certificate on multiple servers always transfer the private key using a secure method (e-mail is not considered a secure method of transfer).
  • It is best practice to ensure that you have current and up to date Ciphers and Protocols to ensure the best security when deploying a new Private key and Server Certificate.
  • Make sure you run the SSL/TLS Server Test at the end of the installation process to check your certificate configuration against SSL/TLS Best Practices.
  • For more information on SSL/TLS Best Practices, click here.

How to install SSL/TLS certificates on Cisco ACS version 5.x series

Pre-requirement:

Cisco Secure ACS version 5.x series. (5.1 to latest). For the installation instructions on legacy version of Cisco Secure ACS version 4.x series or below, please click here.

NOTES : The completion on the steps below will require the appliance to be restarted. So, make sure no user is connected during certificate installation process.

This is a two step process:
1) Root and Intermediate Certificates Installation
2) Server Certificate Installation

Part 1 of 2: Root and Intermediate Certificates Installation

1. Login to your Secure ACS admin portal.

2. On the left column menu, expand Users and Identity Stores, then expand External Identity Stores. Select Certificate Authorities.

3. On certificate authorities window on main screen, click Add button to start importing root certificate.



4. Click on Browse button and locate for root.crt file. Type in the description for this root certificate. You might opt to check the checkbox Trust for client with EAP-TLS. Click Submit button to continue.

5. Your root certificate will be imported and show on the entry inside Certificate Authorities window.

6. Click on the Add button again to continue import the intermediate1 certificate. Click Browse button to locate the file called intermediate1.crt. Fill in the Description field box with the information for this intermediate1 certificate. You might opt to check the checkbox Trust for client with EAP-TLS. Click Submit button to continue.



7. Repeat the above step for intermediate2 certificate.

8. After all the CA certificates have been imported, you should be able to see them all listed on the Certificate Authorities window. At this point the root and intermediate certificates are successfully imported to your appliance.

Part 2 of 2: Server Certificate Installation

1. On the left column menu, expand System Administration and expand Local Server Certificates. Select Local Certificates.

2. On the main screen, click Add button to open certificate creation method window.

3. Select Bind CA Signed Certificate and click Next button to continue

 4. Click on Browse button and locate for ServerCertificate.crt. Check the checkbox for Management Interface. You might opt to check the checkbox for EAP: Used for EAP protocols. Click Finish button

5. The confirmation window will show up. Click OK button to continue. At this point your appliance will be restarted.

6. After your appliance is back online, you can check on the certificate installation by going directly to your URL and check the certificate directly on the address box. Example:


If you have any questions or concerns please contact the Entrust Certificate Services Support department for further assistance: 

Hours of Operation: 
Sunday 8:00 PM ET to Friday 8:00 PM ET 
North America (toll free): 1-866-267-9297 
Outside North America: 1-613-270-2680 (or see the list below) 
NOTE: Smart Phone users may use the 1-800 numbers shown in the table below.
Otherwise, it is very important that international callers dial the UITF format exactly as indicated. Do not dial an extra "1" before the "800" or your call will not be accepted as an UITF toll free call. 

CountryNumber
Australia0011 - 800-3687-7863
1-800-767-513
Austria00 - 800-3687-7863
Belgium00 - 800-3687-7863
Denmark00 - 800-3687-7863
Finland990 - 800-3687-7863 (Telecom Finland)
00 - 800-3687-7863 (Finnet)
France00 - 800-3687-7863
Germany00 - 800-3687-7863
Hong Kong001 - 800-3687-7863 (Voice)
002 - 800-3687-7863 (Fax)
Ireland00 - 800-3687-7863
Israel014 - 800-3687-7863
Italy00 - 800-3687-7863
Japan001 - 800-3687-7863 (KDD)
004 - 800-3687-7863 (ITJ)
0061 - 800-3687-7863 (IDC)
Korea001 - 800-3687-7863 (Korea Telecom)
002 - 800-3687-7863 (Dacom)
Malaysia00 - 800-3687-7863
Netherlands00 - 800-3687-7863
New Zealand00 - 800-3687-7863
0800-4413101
Norway00 - 800-3687-7863
Singapore001 - 800-3687-7863
Spain00 - 800-3687-7863
Sweden00 - 800-3687-7863 (Telia)
00 - 800-3687-7863 (Tele2)
Switzerland00 - 800-3687-7863
Taiwan00 - 800-3687-7863
United Kingdom00 - 800-3687-7863
0800 121 6078
+44 (0) 118 953 3088

 

 

 

 

 

TN9039