153
Submitting a PKI certificate request
When requesting a certificate, an entity introduces itself to the CA by providing its identity information
and public key, which are the major components of the certificate. A certificate request can be submitted
to a CA in offline mode or online mode. In offline mode, a certificate request is submitted to a CA by an
out-of-band method such as phone, disk, or email.
An online certificate request can be submitted in manual mode or auto mode.
Submitting a certificate request in auto mode
In auto mode, an entity automatically requests a certificate from the CA server if it has no local
certificate for an application working with PKI, and then it retrieves the certificate and saves the
certificate locally. Before requesting a certificate, if the PKI domain does not yet have the CA certificate,
the entity automatically retrieves the CA certificate.
To configure an entity to submit a certificate request in auto mode:
To do…
Use the command…
Remarks
1.
Enter system view.
system-view
—
2.
Enter PKI domain view.
pki domain
domain-name
—
3.
Set the certificate request
mode to
auto
.
certificate request mode auto
[
key-length
key
-
length
|
password
{
cipher
|
simple
}
password
] *
Required
Manual by default
In auto mode, an entity does not automatically re-request a certificate to replace a certificate that is
expiring or has expired. After the certificate expires, the service using the certificate might be
interrupted.
Submitting a certificate request in manual mode
In manual mode, you manually submit a certificate request for an entity. Before submitting a certificate
request, you must make sure that an RSA key pair has been generated and that the CA certificate has
been retrieved and saved locally.
The CA certificate is required to verify the authenticity and validity of a local certificate. The public key
of the key pair is an important part of the request information and is transferred to the CA along with
some other information. For more information about RSA key pair configuration, see
Security
Configuration Guide
.
To submit a certificate request in manual mode:
To do…
Use the command…
Remarks
1.
Enter system view.
system-view
—
2.
Enter PKI domain view.
pki domain
domain-name
—
3.
Set the certificate request
mode to
manual
.
certificate request mode manual
Optional.
Manual by default.
4.
Return to system view.
quit
—
5.
Retrieve a CA certificate
manually.
."
Required.
Содержание A5830 Series
Страница 207: ...199 Figure 62 SFTP client interface ...