155
To do…
Use the command…
Remarks
2.
Retrieve a
certificate
manually.
Online
pki retrieval-certificate
{
ca
|
local
}
domain
domain-name
Required.
Use either command.
Offline
pki import-certificate
{
ca
|
local
}
domain
domain
-
name
{
der
|
p12
|
pem
}
[
filename
filename
]
If a PKI domain already has a CA certificate, you cannot retrieve another CA certificate for it. This
restriction helps avoid inconsistency between the certificate and registration information resulting from
configuration changes. To retrieve a new CA certificate, first use the
pki delete-certificate
command to
delete the existing CA certificate and the local certificate.
The pki retrieval-certificate configuration is not saved in the configuration file.
Be sure that the switch’s system time falls in the validity period of the certificate so that the certificate is
valid.
Configuring PKI certificate verification
A certificate needs to be verified before being used. Verifying a certificate involves checking whether the
certificate is signed by the CA and whether the certificate has expired or has been revoked.
You can specify whether to perform CRL checking during certificate verification. If you enable CRL
checking, CRLs are used in verification of a certificate, and you must retrieve the CA certificate and CRLs
to the local switch before the certificate verification. If you disable CRL checking, you only need to
retrieve the CA certificate.
Configuring CRL-checking-enabled PKI certificate verification
To do…
Use the command…
Remarks
1.
Enter system view.
system-view
—
2.
Enter PKI domain view.
pki domain
domain-name
—
3.
Specify the URL of the CRL
distribution point.
crl url
url-string
Optional.
No CRL distribution point URL is
specified by default.
4.
Set the CRL update period.
crl update-period
hours
Optional.
By default, the CRL update period
depends on the next update field
in the CRL file.
5.
Enable CRL checking.
crl check
enable
Optional.
Enabled by default.
6.
Return to system view.
quit
—
7.
Retrieve the CA certificate.
."
Required.
8.
Retrieve CRLs.
pki retrieval-crl domain
domain-
name
Required.
Содержание A5830 Series
Страница 207: ...199 Figure 62 SFTP client interface ...