
12.5 Configuring Certificate Enrollment
Certificate enrollment is a process in which an entity registers with a CA and obtains a certificate
from the CA. During this process, the entity provides the identity information and public key,
which will be added to the certificate issued to the entity.
12.5.1 Establishing the Configuration Task
Before configuring certificate enrollment, familiarize yourself with the applicable environment,
complete the pre-configuration tasks, and obtain the data required for configuration. This will
help you complete the configuration task quickly and accurately.
Applicable Environment
Certificates can be enrolled using the following methods:
l
Manual certificate enrollment: A PKI device is configured to enroll a certificate with a CA.
l
Automatic certificate enrollment: A PKI device uses the Simple Certification Enrollment
Protocol (SCEP) to request a certificate from a CA when the configuration required for
certificate enrollment is complete but no local certificate is available.
l
Self-signed certificate enrollment: A PKI device issues a self-signed certificate to itself.
Pre-configuration Tasks
Before configuring certificate enrollment, complete the following tasks:
l
Creating a PKI entity
l
Creating a PKI domain
Data Preparation
To configure certificate enrollment, you need the following data.
No.
Data
1
PKI domain name and (optional) certificate request
information in PKCS#10 format
2
(Optional) Percentage of the certificate's validity period
3
Self-signed certificate file name
12.5.2 Configuring Manual Certificate Enrollment
An entity can apply to a CA for a certificate online or offline. In offline enrollment mode, the
entity provides the identity information and public key in an outband way. For example, the
entity can make a call or send an email to the CA.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
12 PKI Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
245