NOTE
Certificate contains personal or an enterprise's information and public key:
l
Public key: The two ends share a public key to encrypt data and verify signatures.
l
Private key: Each end has a private key to decrypt data and sign signature.
l
Signature: Information containing a signature cannot be modified by anyone except the creator. It
ensures data security and integrity.
Procedure
Step 1
Run:
system-view
The system view is displayed.
Step 2
Run:
cwmp
The CWMP view is displayed.
Step 3
Run:
cwmp acs url
url
The ACS URL to which the CPE connects is specified.
NOTE
The ACS URL must be in the HTTPS format.
Step 4
Run:
cwmp ssl-client
{
client-root-cert
{
rootcert-path1
} [
rootcert-path2
] |
ssl-
policy
policy-name
}
The CPE is configured to validate the certificate from the ACS.
NOTE
The system time must be correctly set; otherwise, certificate validation may fail. To use a new certificate,
uninstall the existing certificate first.
Before configuring a CPE to authenticate the ACS using an SSL policy, run the
ssl policy
policy-name
type client
command to configure the SSL policy on the CPE.
----End
4.3.6 Checking the Configuration
Prerequisites
All the CWMP configurations are complete.
Procedure
l
Run the
display cwmp configuration
command to check CWMP configurations on the
AR150/200.
l
Run the
display cwmp status
to check CWMP status on the AR150/200.
----End
Huawei AR150&200 Series Enterprise Routers
Configuration Guide - Network Management
4 CWMP Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
103