
l
Router's interface connected to the Internet: Ethernet1/0/0
l
IP address of Ethernet1/0/0: 2.1.1.1/24
l
IP address of the CA: 3.1.1.1/24
l
PKI parameters, as shown in the following table
Item
Data
PKI entity
PKI entity name: admin
l
PKI common name: hello
l
Country code: CN
PKI domain
PKI domain name: admin
l
Trusted CA: ca_root
l
Certificate's enrollment URL: http://
3.1.1.1:8080/certsrv/mscep/mscep.dll
l
Bound PKI entity: admin
l
CA's fingerprint algorithm: secure hash algorithm
(SHA)
Fingerprint:
17A34D94624B1C1BCBF6D763C4A67035D5
B578EAF
l
SSL parameters, as shown in the following table
Policy Name
Maximum Number of
Sessions
Session Timeout Period
adminserver
40
7200 seconds
l
HTTPS service port number: 1278
NOTE
Before starting the configuration, ensure that routes between the Router, user hosts, and CA are reachable.
Procedure
Step 1
Configure a PKI entity and a PKI domain.
# Configure a PKI entity.
<Huawei>
system-view
[Huawei]
sysname Router
[Router]
pki entity admin
[Router-pki-entity-admin]
common-name hello
[Router-pki-entity-admin]
country CN
[Router-pki-entity-admin]
quit
# Configure a PKI domain.
[Router]
pki realm admin
[Router-pki-realm-admin]
entity admin
[Router-pki-realm-admin]
ca id ca_root
[Router-pki-realm-admin]
enrollment-url http://3.1.1.1:8080/certsrv/mscep/
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
2 HTTPS Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
39