
1-7
z
Currently, up to two PKI domains can be created on a device.
z
The CA name is required only when you retrieve a CA certificate. It is not used when in local
certificate request.
z
Currently, the URL of the server for certificate request does not support domain name resolving.
Submitting a PKI Certificate Request
When requesting a certificate, an entity introduces itself to the CA by providing its identity information
and public key, which will be the major components of the certificate. A certificate request can be
submitted to a CA in two ways: online and offline. In offline mode, a certificate request is submitted to a
CA by an “out-of-band” means such as phone, disk, or e-mail.
Online certificate request falls into two categories: manual mode and auto mode.
Submitting a Certificate Request in Auto Mode
In auto mode, an entity automatically requests a certificate through the SCEP from the CA server if it
has no local certificate for an application to work with PKI.
Follow these steps to configure an entity to submit a certificate request in auto mode:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter PKI domain view
pki domain domain-name
—
Set the certificate request mode to
auto
certificate request mode auto
[
key-length key
-
length
|
password
{
cipher
|
simple
}
password
] *
Required
Manual by default
After the certificate is to expire or has expired, the entity does not initiate a re-request automatically. To
have a new local certificate, you need to request one manually.
Submitting a Certificate Request in Manual Mode
In manual mode, you need to retrieve a CA certificate, generate a local RSA key pair, and submit a local
certificate request for an entity.
The goal of retrieving a CA certificate is to verify the authenticity and validity of a local certificate.
Generating an RSA key pair is an important step in certificate request. The key pair includes a public
key and a private key. The private key is kept by the user, while the public key is transferred to the CA
along with some other information. For detailed information about RSA key pair configuration, refer to
Public Key Configuration
in the
Security Volume
.
Follow these steps to submit a certificate request in manual mode:
Содержание S5120-EI Series
Страница 139: ...ii...
Страница 268: ...3 3 SwitchB system view SwitchB interface vlan interface 1 SwitchB Vlan interface1 ip address dhcp alloc...
Страница 328: ...i Table of Contents 1 Dual Stack Configuration 1 1 Dual Stack Overview 1 1 Configuring Dual Stack 1 1...
Страница 578: ...1 21 C...
Страница 739: ...1 12 Enable ARP detection based on 802 1X security entries SwitchB arp detection mode dot1x...
Страница 926: ...2 8...
Страница 942: ...ii Single Device Upgrade 3 4 IRF System Upgrade 3 5...
Страница 985: ...1 1...
Страница 1018: ...1 6...