试验拓扑:
================================下面是层次化PKI配备份==================================
hostname Root-CA
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
clock timezone GMT 8
!
!
ip cef
ip domain name yeslab.net
!
!
ip auth-proxy max-nodata-conns 3
ip admission max-nodata-conns 3
!
multilink bundle-name authenticated
!
!
crypto pki server Root-CA
issuer-name cn=Root-CA.yeslab.net, ou=yeslabsec, o=yeslab, l=qygy701
grant auto
!
crypto pki trustpoint Root-CA
revocation-check crl
rsakeypair Root-CA
!
!
crypto pki certificate chain Root-CA
certificate ca 01
30820281 308201EA A0030201 02020101 300D0609 2A864886 F70D0101 04050030
54311030 0E060355 04071307 71796779 37303131 0F300D06 0355040A 13067965
736C6162 31123010 06035504 0B130979 65736C61 62736563 311B3019 06035504
03131252 6F6F742D 43412E79 65736C61 622E6E65 74301E17 0D313130 37303930
37353434 345A170D 31343037 30383037 35343434 5A305431 10300E06 03550407
13077179 67793730 31310F30 0D060355 040A1306 7965736C 61623112 30100603
55040B13 09796573 6C616273 6563311B 30190603 55040313 12526F6F 742D4341
2E796573 6C61622E 6E657430 819F300D 06092A86 4886F70D 01010105 0003818D
00308189 02818100 B5782222 B5436C90 C4985C3D 8390DBEC DF15C731 B00E1A1C
1DC9C402 B934BF58 5AFD094C 069A197B 01C6D422 3788AE6D E896D690 3D1A0E71
8CF5FCED E07B573C 6C0B4182 A4CE5B83 3C0F9488 FB7F7F26 E70B0D0F C6F2622A
FC735257 B9302D91 F4432CA4 7CA82009 97863F23 55E827AB 22CC6BB9 EBF156A3
1E5232E2 834549D9 02030100 01A36330 61300F06 03551D13 0101FF04 05300301
01FF300E 0603551D 0F0101FF 04040302 0186301F 0603551D 23041830 16801475
126334D2 A442A3A9 7308348C A8A39094 ED00CC30 1D060355 1D0E0416 04147512
6334D2A4 42A3A973 08348CA8 A39094ED 00CC300D 06092A86 4886F70D 01010405
00038181 009BDB04 2635EC7B 68FE949E 43DD952A FB628504 9369AA2F 20127CE4
AB25DA16 A3212311 13811C36 E58AF0D7 E65830E4 9CC8B772 F3CB62B0 0B1C9121
3306B6F8 C925639D 3FA316C5 8D038546 BA61A550 77348027 75E20E9D CEB1498A
32646D8A 103AB928 9CD16E28 B4D6DC13 C1D7A7DC CF5DD3E1 46655B80 9A3D5C2A
39D9F90B 86
quit
!
!
!
!
!
!
!
!
!
!
!
!
archive
log config
hidekeys
!
!
!
!
!
!
!
!
interface FastEthernet0/0
ip address 10.1.1.200 255.255.255.0
duplex auto
speed auto
!
interface FastEthernet0/1
no ip address
shutdown
duplex auto
speed auto
!
interface FastEthernet1/0
no ip address
shutdown
duplex auto
speed auto
!
interface FastEthernet2/0
no ip address
shutdown
duplex auto
speed auto
!
interface FastEthernet3/0
no ip address
shutdown
duplex auto
speed auto
!
ip http server
no ip http secure-server
ip forward-protocol nd
!
!
!
!
!
!
!
control-plane
!
!
!
!
!
!
!
!
!
line con 0
line aux 0
line vty 0 4
!
ntp master
!
end
=====================================================================================
hostname SUB-CA-1
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
clock timezone GMT 8
!
!
ip cef
ip domain name yeslab.net
!
!
ip auth-proxy max-nodata-conns 3
ip admission max-nodata-conns 3
!
multilink bundle-name authenticated
!
!
crypto pki server SUB-CA-1(再配置SUB-CA)
issuer-name cn=SUB-CA-1.yeslab.net, ou=yeslabsec, o=yeslab, l=qygy701
grant auto
mode sub-cs
!
crypto pki trustpoint SUB-CA-1(先配置Trustpoint)
enrollment url http://10.1.1.200:80
subject-name cn=SUB-CA-1.yeslab.net, ou=yeslabsec, o=yeslab, l=qygy701
revocation-check crl
rsakeypair SUB-CA-1
!
!
crypto pki certificate chain SUB-CA-1
certificate 02
3082027F 308201E8 A0030201 02020102 300D0609 2A864886 F70D0101 04050030
54311030 0E060355 04071307 71796779 37303131 0F300D06 0355040A 13067965
736C6162 31123010 06035504 0B130979 65736C61 62736563 311B3019 06035504
03131252 6F6F742D 43412E79 65736C61 622E6E65 74301E17 0D313130 37303930
38303034 305A170D 31323037 30383038 30303430 5A305531 10300E06 03550407
13077179 67793730 31310F30 0D060355 040A1306 7965736C 61623112 30100603
55040B13 09796573 6C616273 6563311C 301A0603 55040313 13535542 2D43412D
312E7965 736C6162 2E6E6574 30819F30 0D06092A 864886F7 0D010101 05000381
8D003081 89028181 00E8EA7B DA3C2BB7 DAC3B4C0 777D4FA7 5A97529B B0056605
88142FCF BFED261A CE92B1A7 B3AE026F 5587A7E8 8187A844 8E5B488E 79AFF9EF
5B5E5D9F 3885292F 2C05320C 9248EE72 9D347EAF 157BF220 510D04F3 4B9FA924
856BD6ED C2D27272 47F7356D B62C5AF2 2CF21F16 96D86ED9 F5D455F2 2DAD83CC
F6351188 913329FB DF020301 0001A360 305E300F 0603551D 130101FF 04053003
0101FF30 0B060355 1D0F0404 03020780 301F0603 551D2304 18301680 14751263
34D2A442 A3A97308 348CA8A3 9094ED00 CC301D06 03551D0E 04160414 9DC56EC1
4B6C16C3 9D993F30 BCE7D5F5 AFB59140 300D0609 2A864886 F70D0101 04050003
818100AD 33C2DFA3 C62F8F88 FC0E3BC1 93C0546D 6DCE2552 E266B50D 9EB9B23B
5DBCBCB4 362C7F17 CFB7D9CF 2C43A045 1FA90D59 0D028536 24268254 1BCFACF2
14204679 F4BB1C9A B10B870D 70363950 F13E976E 3D8C2E9B CBA73BA0 43FD2063
0425F20E 3E030A2A 3FB0074F B4341DD2 9635BE27 7D17341C F5B0639C DB287EC0
0797B6
quit
certificate ca 01
30820281 308201EA A0030201 02020101 300D0609 2A864886 F70D0101 04050030
54311030 0E060355 04071307 71796779 37303131 0F300D06 0355040A 13067965
736C6162 31123010 06035504 0B130979 65736C61 62736563 311B3019 06035504
03131252 6F6F742D 43412E79 65736C61 622E6E65 74301E17 0D313130 37303930
37353434 345A170D 31343037 30383037 35343434 5A305431 10300E06 03550407
13077179 67793730 31310F30 0D060355 040A1306 7965736C 61623112 30100603
55040B13 09796573 6C616273 6563311B 30190603 55040313 12526F6F 742D4341
2E796573 6C61622E 6E657430 819F300D 06092A86 4886F70D 01010105 0003818D
00308189 02818100 B5782222 B5436C90 C4985C3D 8390DBEC DF15C731 B00E1A1C
1DC9C402 B934BF58 5AFD094C 069A197B 01C6D422 3788AE6D E896D690 3D1A0E71
8CF5FCED E07B573C 6C0B4182 A4CE5B83 3C0F9488 FB7F7F26 E70B0D0F C6F2622A
FC735257 B9302D91 F4432CA4 7CA82009 97863F23 55E827AB 22CC6BB9 EBF156A3
1E5232E2 834549D9 02030100 01A36330 61300F06 03551D13 0101FF04 05300301
01FF300E 0603551D 0F0101FF 04040302 0186301F 0603551D 23041830 16801475
126334D2 A442A3A9 7308348C A8A39094 ED00CC30 1D060355 1D0E0416 04147512
6334D2A4 42A3A973 08348CA8 A39094ED 00CC300D 06092A86 4886F70D 01010405
00038181 009BDB04 2635EC7B 68FE949E 43DD952A FB628504 9369AA2F 20127CE4
AB25DA16 A3212311 13811C36 E58AF0D7 E65830E4 9CC8B772 F3CB62B0 0B1C9121
3306B6F8 C925639D 3FA316C5 8D038546 BA61A550 77348027 75E20E9D CEB1498A
32646D8A 103AB928 9CD16E28 B4D6DC13 C1D7A7DC CF5DD3E1 46655B80 9A3D5C2A
39D9F90B 86
quit
!
!
!
!
!
!
!
!
!
!
!
!
archive
log config
hidekeys
!
!
!
!
!
!
!
!
interface FastEthernet0/0
ip address 10.1.1.201 255.255.255.0
duplex auto
speed auto
!
interface FastEthernet0/1
no ip address
shutdown
duplex auto
speed auto
!
interface FastEthernet1/0
no ip address
shutdown
duplex auto
speed auto
!
interface FastEthernet2/0
no ip address
shutdown
duplex auto
speed auto
!
interface FastEthernet3/0
no ip address
shutdown
duplex auto
speed auto
!
ip http server
no ip http secure-server
ip forward-protocol nd
!
!
!
!
!
!
!
control-plane
!
!
!
!
!
!
!
!
!
line con 0
line aux 0
line vty 0 4
!
ntp clock-period 17179832
ntp server 10.1.1.200
!
end
==============================================================================
hostname SUB-CA-2
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
clock timezone GMT 8
!
!
ip cef
ip domain name yeslab.net
!
!
ip auth-proxy max-nodata-conns 3
ip admission max-nodata-conns 3
!
multilink bundle-name authenticated
!
!
crypto pki server SUB-CA-2(再配置SUB-CA)
issuer-name cn=SUB-CA-2.yeslab.net, ou=yeslabsec, o=yeslab, l=qygy701
grant auto
mode sub-cs
!
crypto pki trustpoint SUB-CA-2(先配置Trustpoint)
enrollment url http://10.1.1.200:80
subject-name cn=SUB-CA-2.yeslab.net, ou=yeslabsec, o=yeslab, l=qygy701
revocation-check crl
rsakeypair SUB-CA-2
!
!
crypto pki certificate chain SUB-CA-2
certificate 03
3082027F 308201E8 A0030201 02020103 300D0609 2A864886 F70D0101 04050030
54311030 0E060355 04071307 71796779 37303131 0F300D06 0355040A 13067965
736C6162 31123010 06035504 0B130979 65736C61 62736563 311B3019 06035504
03131252 6F6F742D 43412E79 65736C61 622E6E65 74301E17 0D313130 37303930
38303334 305A170D 31323037 30383038 30333430 5A305531 10300E06 03550407
13077179 67793730 31310F30 0D060355 040A1306 7965736C 61623112 30100603
55040B13 09796573 6C616273 6563311C 301A0603 55040313 13535542 2D43412D
322E7965 736C6162 2E6E6574 30819F30 0D06092A 864886F7 0D010101 05000381
8D003081 89028181 00CD7427 073403A1 1DFDE953 7D89429A 32A9EEFC A91D33FE
D885B918 0DEF3F78 011F371B FE08A046 02E31DDF F05BCAA4 797D61ED 74152889
57F5F737 65981D55 D9BD4D00 EB537F62 E7104B67 50B93DBD 3F5A870B 386FCE08
CC4DB429 1D53BE19 60A77ADB 7C989BC0 FC7E29B3 FAB000DD 2ED50B9E 5284C58F
1D0146B6 FFF3B86B 07020301 0001A360 305E300F 0603551D 130101FF 04053003
0101FF30 0B060355 1D0F0404 03020780 301F0603 551D2304 18301680 14751263
34D2A442 A3A97308 348CA8A3 9094ED00 CC301D06 03551D0E 04160414 5A8D795A
BB7D8FC8 0C966384 B9FE8EB6 7967890E 300D0609 2A864886 F70D0101 04050003
8181000F 3A6ABB70 1E1A3D7C ACADA943 07379F4D 31524AFA 26903DEC CAFC11EB
B14E8CED 264AB684 BBC08081 0B1849DA A189EBC7 6BEFD441 08945C93 6631D4A8
F33B336E 8BEF837B 0B85864A F06DFE49 9F24A360 F208750E 321DADDF BB604ED8
E83805D1 A4E8BB2D 3FBB47E0 6DD908E5 34D6879D 0F72F8DE 0050D1A3 ADC1AD98
EDB785
quit
certificate ca 01
30820281 308201EA A0030201 02020101 300D0609 2A864886 F70D0101 04050030
54311030 0E060355 04071307 71796779 37303131 0F300D06 0355040A 13067965
736C6162 31123010 06035504 0B130979 65736C61 62736563 311B3019 06035504
03131252 6F6F742D 43412E79 65736C61 622E6E65 74301E17 0D313130 37303930
37353434 345A170D 31343037 30383037 35343434 5A305431 10300E06 03550407
13077179 67793730 31310F30 0D060355 040A1306 7965736C 61623112 30100603
55040B13 09796573 6C616273 6563311B 30190603 55040313 12526F6F 742D4341
2E796573 6C61622E 6E657430 819F300D 06092A86 4886F70D 01010105 0003818D
00308189 02818100 B5782222 B5436C90 C4985C3D 8390DBEC DF15C731 B00E1A1C
1DC9C402 B934BF58 5AFD094C 069A197B 01C6D422 3788AE6D E896D690 3D1A0E71
8CF5FCED E07B573C 6C0B4182 A4CE5B83 3C0F9488 FB7F7F26 E70B0D0F C6F2622A
FC735257 B9302D91 F4432CA4 7CA82009 97863F23 55E827AB 22CC6BB9 EBF156A3
1E5232E2 834549D9 02030100 01A36330 61300F06 03551D13 0101FF04 05300301
01FF300E 0603551D 0F0101FF 04040302 0186301F 0603551D 23041830 16801475
126334D2 A442A3A9 7308348C A8A39094 ED00CC30 1D060355 1D0E0416 04147512
6334D2A4 42A3A973 08348CA8 A39094ED 00CC300D 06092A86 4886F70D 01010405
00038181 009BDB04 2635EC7B 68FE949E 43DD952A FB628504 9369AA2F 20127CE4
AB25DA16 A3212311 13811C36 E58AF0D7 E65830E4 9CC8B772 F3CB62B0 0B1C9121
3306B6F8 C925639D 3FA316C5 8D038546 BA61A550 77348027 75E20E9D CEB1498A
32646D8A 103AB928 9CD16E28 B4D6DC13 C1D7A7DC CF5DD3E1 46655B80 9A3D5C2A
39D9F90B 86
quit
!
!
!
!
!
!
!
!
!
!
!
!
archive
log config
hidekeys
!
!
!
!
!
!
!
!
interface FastEthernet0/0
ip address 10.1.1.202 255.255.255.0
duplex auto
speed auto