
Procedure
Step 1
Configure interface IP addresses and routes to enable IPSec peers and CA to communicate.
Step 2
Configure a PKI entity.
# Configure RouterA.
<Huawei>
system-view
[Huawei]
pki entity routera
[Huawei-pki-entity-routera]
common-name helloa
[Huawei-pki-entity-routera]
country cn
[Huawei-pki-entity-routera]
state jiangsu
[Huawei-pki-entity-routera]
organization huawei
[Huawei-pki-entity-routera]
organization-unit info
[Huawei-pki-entity-routera]
quit
# Configure RouterB.
<Huawei>
system-view
[Huawei]
pki entity routerb
[Huawei-pki-entity-routerb]
common-name hellob
[Huawei-pki-entity-routerb]
country cn
[Huawei-pki-entity-routerb]
state jiangsu
[Huawei-pki-entity-routerb]
organization huawei
[Huawei-pki-entity-routerb]
organization-unit marketing
[Huawei-pki-entity-routerb]
quit
Step 3
Configure a PKI domain.
# Configure RouterA.
[Huawei]
pki realm testa
[Huawei-pki-realm-testa]
ca id ca_root
[Huawei-pki-realm-testa]
entity routera
[Huawei-pki-realm-testa]
enrollment-url http://10.137.145.158:8080/certsrv/mscep/
mscep.dll ra
[Huawei-pki-realm-testa]
fingerprint sha1 7A34D94624B1C1BCBF6D763C4A67035D5B578EAF
[Huawei-pki-realm-testa]
certificate-check none
[Huawei-pki-realm-testa]
quit
#Configure RouterB.
[Huawei]
pki realm testb
[Huawei-pki-realm-testb]
ca id ca_root
[Huawei-pki-realm-testb]
entity routerb
[Huawei-pki-realm-testb]
enrollment-url http://10.137.145.158:8080/certsrv/mscep/
mscep.dll ra
[Huawei-pki-realm-testb]
fingerprint sha1 7A34D94624B1C1BCBF6D763C4A67035D5B578EAF
[Huawei-pki-realm-testb]
certificate-check none
[Huawei-pki-realm-testb]
quit
Step 4
Configure IKE to use a digital signature for identity authentication.
# Configure RouterA.
[Huawei]
ike proposal 1
[Huawei-ike-proposal-1]
encryption-algorithm 3des-cbc
[Huawei-ike-proposal-1]
authentication-method rsa-signature
[Huawei-ike-proposal-1]
authentication-algorithm sha1
[Huawei-ike-proposal-1]
quit
[Huawei]
ike peer routera v2
[Huawei-ike-peer-routera]
ike-proposal 1
[Huawei-ike-peer-routera]
local-address 1.1.1.1
[Huawei-ike-peer-routera]
remote-address 2.2.2.1
[Huawei-ike-peer-routera]
pki realm testa
# Configure RouterB.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
12 PKI Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
257