220
Step Command
Remarks
7.
Set the unit of the entity in
the organization.
organization-unit
org-unit-name
By default, the unit is not set.
8.
Set the state where the entity
resides.
state
state-name
By default, the state is not set.
9.
Set the FQDN of the entity.
fqdn
fqdn-name-string
By default, the FQDN is not set.
10.
Configure the IP address of
the entity.
ip
{
ip-address
|
interface
interface-type
interface-number
}
By default, the IP address is not
configured.
Configuring a PKI domain
A PKI domain contains enrollment information for a PKI entity. It is locally significant and is intended only
for reference by other applications like IKE and SSL.
To configure a PKI domain:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Create a PKI domain
and enter its view.
pki domain
domain-name
By default, no PKI domains exist.
3.
Specify the trusted CA.
ca identifier
name
By default, no trusted CA is
specified.
To obtain a CA certificate, the
trusted CA name must be provided.
The trusted CA name uniquely
identifies the CA to be used if
multiple CAs exist on the same CA
server. The CA server's URL is
specified by using the
certificate
request url
command.
4.
Specify the PKI entity
name.
certificate request entity
entity-name
By default, no entity is specified.
5.
Specify the type of
certificate request
reception authority.
certificate request from
{
ca
|
ra
}
By default, no authority type is
specified.
6.
Specify the certificate
request URL.
certificate request url
url-string
By default, the certificate request
URL is not specified.
Do not configure this command
when you request a certificate in
offline mode.
7.
(Optional.) Set the
SCEP polling interval
and maximum number
of polling attempts.
certificate request polling
{
count
count
|
interval
minutes
}
By default, the switch polls the CA
server for the certificate request
status every 20 minutes. The
maximum number of polling
attempts is 50.