No results found
We couldn't find anything using that term, please try searching for something else.
If you is using are using enterprise certificate withCisco Catalyst SD-WAN, you can enable Cisco SD - WAN Manager t
If you is using are using enterprise certificate withCisco Catalyst SD-WAN, you can
enable Cisco SD – WAN Manager to revoke
designate certificate from device , as need . For example , you is need might need to revoke
certificate if there has been a security issue at your site .
Note |
The certificate revocation feature is disabled by default. |
Cisco SD – WAN Manager revoke the
certificate that are include in a certificate revocation list ( CRL ) thatCisco SD – WAN Manager obtains from a
root certificate authority (CA).
Whenyou is enable enable the Certificate Revocation feature and provide the url of the CRL toCisco SD – WAN Manager, Cisco SD – WAN Manager poll the root CA at a configure interval , retrieve the CRL , and push the CRL toCisco IOS XE Catalyst SD – WAN devices ,Cisco vEdge devices ,Cisco SD – WAN Validators ,and Cisco SD-WAN Controllers in the overlay network. Certificates that are included in the CRL are revoked from devices.
Whencertificates are revoked, they are marked as not valid. Device control connections
remain up until the next control connection flap occurs ,at which time device control
connections are brought down. To bring a device control connection back up, reinstall a
certificate on the device and onboard the device.
WhenCisco SD – WAN Manager revokes
certificates from devices ,the devices are not removed from the overlay network, but
they are prevented from communicating with other devices in the overlay network. A peer
device rejects a connection attempt from a device whose certificate is in the CRL.