
Procedure
Step 1
Run:
system-view
The system view is displayed.
Step 2
Run:
pki realm
realm-name
A PKI domain is created.
By default, no PKI domain is configured on the AR1200-S.
----End
12.4.3 Configuring a PKI Entity Name
In a PKI domain, configure a name for the PKI entity applying for a certificate. A PKI entity
name binds to only one PKI entity.
Context
When a PKI entity sends a certificate request to a CA, the PKI entity must specify the used entity
name to show its identity information to the CA.
Procedure
Step 1
Run:
system-view
The system view is displayed.
Step 2
Run:
pki realm
realm-name
A PKI domain is configured.
By default, no PKI domain is configured on the AR1200-S.
Step 3
Run:
entity
entity-name
A PKI entity is specified.
By default, no PKI entity is specified on the AR1200-S.
----End
12.4.4 Configuring the Trusted CA Name and Enrollment URL
A trusted authentication authority enrolls and issues certificates to entities. Therefore, a trusted
CA name and enrollment URL must be configured.
Context
A registration authority (RA) receives registration requests from users, checks users' certificate
credentials, and decides whether a CA can issue digital certificates to the users. An RA does not
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
12 PKI Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
241