![HP Compaq Presario,Presario 1910 Скачать руководство пользователя страница 464](http://html.mh-extra.com/html/hp/compaq-presario-presario-1910/compaq-presario-presario-1910_user-manual_161851464.webp)
451
PKI operation
The following describes how a PKI entity requests a local certificate from a CA, and how an RA is
involved in entity enrollment:
1.
A PKI entity submits a certificate request to the CA.
2.
The RA verifies the identity of the entity and sends a digital signature containing the identity
information and the public key to the CA
3.
The CA verifies the digital signature, approves the application, and issues a certificate.
4.
The RA receives the certificate from the CA, sends it to the LDAP server to provide directory
navigation service, and notifies the entity that the certificate is successfully issued.
5.
The entity retrieves the certificate. With the certificate, the entity can communicate with other
entities safely through encryption and digital signature.
6.
The entity makes a request to the CA when it needs to revoke its certificate. The CA approves the
request, updates the CRLs and publishes the CRLs on the LDAP server.
Configuring PKI
The device supports the following PKI certificate request modes:
•
Manual
—In manual mode, you need to retrieve a CA certificate, generate a local RSA key pair,
and submit a local certificate request for an entity.
•
Auto
—In auto mode, an entity automatically requests a certificate through the Simple Certification
Enrollment Protocol (SCEP) when it has no local certificate or the present certificate is about to
expire.
You can specify the PKI certificate request mode for a PKI domain. Different PKI certificate request modes
require different configurations.
Recommended configuration procedure for manually
requesting a certificate
Step Remarks
1.
Creating a PKI entity
(Required.)
Create a PKI entity and configure the identity information.
A certificate is the binding of a public key and the identity information of an
entity, where the identity information is identified by an entity distinguished
name (DN). A CA identifies a certificate applicant uniquely by an entity DN.
IMPORTANT:
The DN settings of an entity must be compliant to the CA certificate issue policy
for confirming which entity parameters are mandatory or optional. Otherwise,
the certificate request might be rejected.
Содержание Compaq Presario,Presario 1910
Страница 35: ...22 Figure 16 Sort display based on MAC address in the ascending order ...
Страница 54: ...41 Figure 27 Configuration finishes ...
Страница 70: ...57 Figure 42 Configuring idle timeout period 3 Set the idle timeout period for logged in users 4 Click Apply ...
Страница 98: ...85 Figure 67 Displaying the rate settings of ports ...
Страница 114: ...101 Figure 82 Port traffic statistics NOTE When the bandwidth utilization is lower than 1 1 is displayed ...
Страница 158: ...145 Field Description OutErrors Number of invalid packets sent through the interface ...
Страница 202: ...189 Figure 177 Creating a static MAC address entry ...
Страница 230: ...217 Figure 193 Configuring MSTP globally on Switch D ...
Страница 359: ...346 5 View the operation result in the Summary area Figure 316 IPv6 traceroute operation result ...