data:image/s3,"s3://crabby-images/a34c8/a34c804bc8c9c41558daa62242ac72ea9fda8ba6" alt="Huawei AR1200-S Series Configuration Manual Download Page 240"
Procedure
Step 1
Configure a PKI entity and a PKI domain.
# Configure a PKI entity.
<Huawei>
system-view
[Huawei]
sysname Router
[Router]
pki entity users
[Router-pki-entity-users]
common-name hello
[Router-pki-entity-users]
country cn
[Router-pki-entity-users]
state jiangsu
[Router-pki-entity-users]
organization huawei
[Router-pki-entity-users]
organization-unit info
[Router-pki-entity-users]
quit
NOTE
If the entity name and entity common name are not set to the Router's IP address 11.1.1.1, the system will
display a message indicating that the certificate is invalid when the client opens a website. This does not
affect HTTPS application.
# Configure a PKI domain, and enable the automatic certificate enrollment and update function.
[Router]
pki realm users
[Router-pki-realm-users]
entity users
[Router-pki-realm-users]
ca id ca_root
[Router-pki-realm-users]
enrollment-url http://11.137.145.158:8080/certsrv/mscep/
mscep.dll ra
[Router-pki-realm-users]
fingerprint sha1 7bb05ada0482273388ed4ec228d79f77309ea3f4
[Router-pki-realm-users]
auto-enroll regenerate
[Router-pki-realm-users]
quit
Step 2
Configure a server SSL policy
sslserver
.
# Create a server SSL policy and specify PKI domain
users
in the policy. This allows the
Router to obtain a digital certificate from the CA specified in the PKI domain.
[Router]
ssl policy sslserver type server
[Router-ssl-policy-sslserver]
pki-realm users
# Set the maximum number of sessions that can be saved and the timeout period of a session.
[Router-ssl-policy-sslserver]
session cachesize 40 timeout 7200
[Router-ssl-policy-sslserver]
quit
Step 3
Configure the Router as an HTTPS server.
# Apply the SSL policy
sslserver
to the HTTPS service.
[Router]
http secure-server ssl-policy sslserver
# Enable the HTTPS server function on the Router.
[Router]
http secure-server enable
# Configure the port number of the HTTPS service.
[Router]
http secure-server port 1278
Step 4
Verify the configuration.
# Run the
display ssl policy
command to view the configuration of the SSL policy
sslserver
.
<Router>
display ssl policy sslserver
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
11 SSL Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
226