
11.1 SSL Overview...............................................................................................................................................218
11.2 SSL Features Supported by the AR1200-S..................................................................................................220
11.3 Configuring a Server SSL Policy.................................................................................................................220
11.4 Configuring a Client SSL Policy..................................................................................................................222
11.5 Configuration Examples...............................................................................................................................224
11.5.1 Example for Configuring a Server SSL Policy...................................................................................224
11.5.2 Example for Configuring a Client SSL Policy....................................................................................227
12.1 PKI Overview...............................................................................................................................................234
12.2 PKI Features Supported by the AR1200-S...................................................................................................235
12.3 Configuring a PKI Entity..............................................................................................................................237
12.3.1 Establishing the Configuration Task...................................................................................................237
12.3.2 Configuring a PKI Entity Identifier.....................................................................................................238
12.3.3 (Optional) Configuring PKI Entity Attributes.....................................................................................238
12.3.4 Checking the Configuration.................................................................................................................239
12.4.1 Establishing the Configuration Task...................................................................................................240
12.4.2 Creating a PKI Domain.......................................................................................................................240
12.4.3 Configuring a PKI Entity Name..........................................................................................................241
12.4.4 Configuring the Trusted CA Name and Enrollment URL...................................................................241
12.4.5 (Optional) Configuring CA Certificate Fingerprint.............................................................................242
12.4.6 (Optional) Configuring a Certificate Revocation Password................................................................243
12.4.7 (Optional) Configuring the RSA Key Length of Certificates..............................................................243
12.4.8 (Optional) Configuring a Source IP Address for TCP Connection Setup...........................................244
12.4.9 Checking the Configuration.................................................................................................................244
12.5.1 Establishing the Configuration Task...................................................................................................245
12.5.2 Configuring Manual Certificate Enrollment........................................................................................245
12.5.3 Configuring Automatic Certificate Enrollment and Update................................................................246
12.5.4 Creating a Self-signed Certificate or Local Certificate.......................................................................247
12.5.5 Checking the Configuration.................................................................................................................247
12.6.1 Establishing the Configuration Task...................................................................................................247
12.6.2 Configuring the Certificate Check Mode............................................................................................248
12.6.3 Checking Certificate Validity..............................................................................................................249
12.6.4 Checking the Configuration.................................................................................................................250
12.7.1 Deleting a Certificate...........................................................................................................................250
12.7.2 Importing a Certificate.........................................................................................................................250
12.7.3 Exporting a Certificate.........................................................................................................................251
12.7.4 Configuring the Default Path Where Certificates Are Stored.............................................................251
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
Contents
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
xi