249
•
After a new certificate is obtained, do not use the
public-key local create
or
public-key local
destroy
command to generate or destroy a key pair with the same name as the key pair in the
local certificate. Otherwise, the existing local certificate becomes unavailable.
•
A PKI domain can have local certificates using only one type of cryptographic algorithms (DSA,
ECDSA, or RSA). If DSA or ECDSA is used, a PKI domain can have only one local certificate. If
RSA is used, a PKI domain can have one local certificate for signature, and one local certificate
for encryption.
Configuring automatic certificate request
IMPORTANT:
The device does not support automatic certificate rollover. To avoid service interruptions, you must
manually submit a certificate renewal request before the current certificate expires.
In auto request mode, when an application works with a PKI entity that does not have a local
certificate, the entity automatically submits a certificate request to the CA. After obtaining the
certificate from the CA, the PKI entity saves the certificate at the local in the PKI domain.
A CA certificate must be present before you request a local certificate. If no CA certificate exists in the
PKI domain, the PKI entity automatically obtains a CA certificate before sending a certificate request.
To configure automatic certificate request:
Step Command Remarks
1.
Enter system view.
system-view
N/A
2.
Enter PKI domain view.
pki domain
domain-name
N/A
3.
Set the certificate request
mode to auto.
certificate request mode auto
[
password
{
cipher
|
simple
}
password
]
By default, the manual
request mode applies.
In auto request mode, set
a password for certificate
revocation as required by
the CA policy.
Manually requesting a certificate
Before you manually submit a certificate request, make sure the CA certificate exists and a key pair
is specified for the PKI domain:
•
The CA certificate is used to verify the authenticity and validity of the obtained local certificate.
•
The key pair is used for certificate request. Upon receiving the public key and the identity
information, the CA signs and issues a certificate.
After the CA issues the certificate, the device obtains and saves it locally.
To manually request a certificate:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter PKI domain view.
pki domain
domain-name
N/A
3.
Set the certificate
request mode to
manual.
certificate request mode manual
By default, the manual request
mode applies.
4.
Return to system view.
quit
N/A
Summary of Contents for 10500 series
Page 326: ...312 No duration limit for this SA ...