This TCL script can be run on an IOS device via a kron schedule and will allow the relevant files stored on NVRAM of the device to be copied to an FTP server, allowing the Certificate Authority to be backed up and subsequently restored, as per the Cisco design guide for Digital Certificates/PKI.
- In backup_ca.tcl, edit the
ftp_server
andftp_path
variables. - Copy the script to the IOS device, e.g. to flash:
- On the device, set
ip ftp username
andip ftp password
and if appropriateip ftp source-interface
- On the device, configure a kron schedule. For example:
kron policy-list BACKUP_CA
cli tclsh flash:/backup_ca.tcl
kron occurance DAILY at 04:00 recurring
policy-list BACKUP_CA