
137
CAUTION:
If you change the storage path, save the configuration before you reboot or shut down the device to avoid
loss of the certificates or the CRLs.
The device has a default storage path for the obtained local certificates and CRLs. You can change the
storage path and specify different paths for the certificates and CRLs.
After you change the storage path for the certificates or CRLs, the certificate files (with the file
extension .cer or .p12) and CRL files (with the extension .crl) in the original path are moved to the new
path.
To specify the storage path for the certificates and CRLs:
Task Command
Remarks
Specify the storage path for
the certificates and CRLs.
pki storage
{
certificates
|
crls
}
dir-path
By default, the storage path for the certificates
and CRLs is the PKI directory on the storage
media of the device.
Exporting certificates
IMPORTANT:
To export all certificates in the PKCS12 format, the PKI domain must have at least one local certificate.
Otherwise, the export operation fails.
To back up or import certificates, you can export the CA certificate and the local certificates in a PKI
domain to local files or display them on a terminal.
When you export a local certificate with the RSA key pair, the name of the target file might not be the
same as specified in the command. It depends on the purpose of the key pair of the certificate.
To export certificates:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Export certificates.
•
Export certificates in DER format:
pki export
domain
domain
-
name
der
{
all
|
ca
|
local
}
filename
filename
•
Export certificates in PKCS12 format:
pki export
domain
domain
-
name
p12
{
all
|
local
}
passphrase
p12passwordstring
filename
filename
•
Export certificates in PEM format:
pki export
domain
domain
-
name
pem
{ {
all
|
local
} [ {
3des-cbc
|
aes-128-cbc
|
aes-192-cbc
|
aes-256-cbc
|
des-cbc
}
pempasswordstring
]
|
ca
} [
filename
filename
]
Configure at least one
command.
If you do not specify a file name
when you export a certificate in
PEM format, the certificate is
displayed on the terminal.