Operation Manual – SSL-HTTPS
H3C S3610&S5510 Series Ethernet Switches
Chapter 2 HTTPS Configuration
2-5
2.8 HTTPS Configuration Example
I. Network requirements
z
Host acts as the HTTPS client and Switch acts as the HTTPS server.
z
Host accesses Switch through Web to control Switch.
z
CA (Certificate Authority) issues certificate to Switch. The common name of CA is
new-ca
.
Caution:
In this configuration example, Windows Server serves as CA and you need to install
Simple Certificate Enrollment Protocol (SCEP) component.
II. Network diagram
Figure 2-1
Network diagram for HTTPS configuration
III. Configuration procedure
Perform the following configurations on Switch:
1)
Apply for a certificate for Switch
# Configure a PKI entity.
<Switch> system-view
[Switch] pki entity en
[Switch-pki-entity-en] common-name http-server1
[Switch-pki-entity-en] fqdn ssl.security.com
[Switch-pki-entity-en] quit
# Configure a PKI domain.
[Switch] pki domain 1
[Switch-pki-domain-1] ca identifier ca1