Operation Manual – PKI
H3C S5500-EI Series Ethernet Switches
Chapter 1 PKI Configuration
1-15
To do…
Use the command…
Remarks
Display information about
one or all certificate
attribute groups
display pki certificate
attribute-group
{
group-name
|
all
}
Available in
any view
Display information about
one or all certificate
attribute-based access
control policies
display pki certificate
access-control-policy
{
policy-name
|
all
}
Available in
any view
1.12 PKI Configuration Examples
Caution:
z
The SCEP plug-in is required when you use the Windows Server as the CA. In this
case, when configuring the PKI domain, you need to use the
certificate request
from ra
command to specify that the entity requests a certificate from an RA.
z
The SCEP plug-in is not required when RSA Keon is used. In this case, when
configuring a PKI domain, you need to use the
certificate request from ca
command to specify that the entity requests a certificate from a CA.
1.12.1 Configuring a PKI Entity to Request a Certificate from a CA
Note:
RSA Keon is used on the CA server in this configuration example.
I. Network requirements
z
The device submits a local certificate request to the CA server.
z
The device acquires the CRLs for certificate validation.