192
Follow these steps to configure a PKI domain:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Create a PKI domain and enter its
view
pki domain
domain-name
Required
No PKI domain exists by default.
Specify the trusted CA
ca
identifier
name
Required
No trusted CA is specified by
default.
Specify the entity for certificate
request
certificate request entity
entity-
name
Required
No entity is specified by default.
The specified entity must exist.
Specify the authority for certificate
request
certificate request from
{
ca
|
ra
}
Required
No authority is specified by
default.
Configure the URL for certificate
request
certificate request url
url-string
Required
No certificate request URL is
configured by default.
Configure the polling interval and
attempt limit for querying the
certificate request status
certificate request polling
{
count
count
|
interval
minutes
}
Optional
The polling is executed for up to
50 times at the interval of 20
minutes by default.
Specify the LDAP server
ldap-server
ip
ip-address
[
port
port-number
] [
version
version-
number
]
Optional
No LDP server is specified by
default.
Configure the fingerprint for root
certificate verification
root-certificate fingerprint
{
md5
|
sha1
}
string
Required when the certificate
request mode is auto and optional
when the certificate request mode
is manual. In the latter case, if you
do not configure this command,
the fingerprint of the root
certificate must be verified
manually.
No fingerprint is configured by
default.
NOTE:
Up to two PKI domains can be created on a device.
The CA name is required only when you retrieve a CA certificate. It is not used when in local certificate request.
The certificate request URL does not support domain name resolution.
Submitting a PKI certificate request
When requesting a certificate, an entity introduces itself to the CA by providing its identity information
and public key, which will be the major components of the certificate. A certificate request can be