74
MDS Orbit MCR-4G Technical Manual
MDS 05-6628A01, Rev. B
admin@(none) 00:27:14> request pki get-cacert scep cert-server-name ex_scep_serv ca-issuer-name
ex_ca_serv
is-valid true
[ok][2012-06-23 00:27:47]
admin@(none) 00:27:47> show pki
KEY KEY
IDENTITY LENGTH KEY DATE TIME
----------------------------------------
ex_key 2048 2012-06-20T10:46:59Z
ex_key_1 2048 2012-06-19T04:36:26Z
CACERT
IDENTITY
----------
ex_ca_server
ex_ca_server_ENC
ex_ca_server_SGN
Additional CA server files sent as part of the request and needed later are saved with the base name
you selected for the CA server and an added extension. Some of the names that may be added are:
·
_ENC , encryption file
·
_SGN , signing file
·
_ISS , issuing file
·
_INT , intermediate file
The second step is to request a client cert from the CA server via the SCEP server.
admin@(none) 06:28:39> request pki get-clientcert scep cert-server-name ex_scep_serv
cert-info-name my_ca_serv ca-issuer-name ex_ca_server cert-identification-name ex_c_cert
cert-key-name ex_key_1 ca-challenge KoCZOBkaOH
is-valid true
[ok][2012-06-20 06:32:04]
admin@(none) 06:32:04> show pki
KEY KEY
IDENTITY LENGTH KEY DATE TIME
----------------------------------------
ex_key 2048 2012-06-20T10:46:59Z
ex_key_1 2048 2012-06-19T04:36:26Z
CACERT
IDENTITY
----------
ex_ca_server
ex_ca_server_ENC
ex_ca_server_SGN
CERT
IDENTITY
----------
ex_c_cert