342
Configuration guidelines
When you configure PKI, follow these guidelines:
•
Make sure the clocks of entities and the CA are synchronous. Otherwise, the validity period of
certificates will be abnormal.
•
The Windows 2000 CA server has some restrictions on the data length of a certificate request.
If the PKI entity identity information in a certificate request goes beyond a certain limit, the
server will not respond to the certificate request.
•
The SCEP plug-in is required when you use the Windows Server as the CA. In this case,
specify
RA
as the authority for certificate request when you configure the PKI domain.
•
The SCEP plug-in is not required when you use the RSA Keon software as the CA. In this case,
specify
CA
as the authority for certificate request when you configure the PKI domain.
Summary of Contents for FlexNetwork NJ5000
Page 12: ...x Index 440 ...
Page 39: ...27 Figure 16 Configuration complete ...
Page 67: ...55 Figure 47 Displaying the speed settings of ports ...
Page 78: ...66 Figure 59 Loopback test result ...
Page 158: ...146 Figure 156 Creating a static MAC address entry ...
Page 183: ...171 Figure 171 Configuring MSTP globally on Switch D ...
Page 243: ...231 Figure 237 IPv6 active route table ...