
426
Step Remarks
5.
Requesting a local
certificate
Required.
When requesting a certificate, an entity introduces itself to the CA by
providing its identity information and public key. The identity information
and public key are the major components of the certificate.
A certificate request can be submitted to a CA in online mode or offline
mode.
•
In online mode, if the request is granted, the local certificate will be sent
to the local system automatically.
•
In offline mode, you must retrieve the local certificate by using an
out-of-band means such as phone, disk, or email.
IMPORTANT:
If a local certificate already exists, you cannot perform the local certificate
retrieval operation. To avoid a possible mismatch between the local certificate
and registration information, you must remove the CA certificate and local
certificate first.
6.
Destroying the RSA key pair
Optional.
Delete the existing RSA key pair and the corresponding local certificate.
If the certificate to be retrieved contains an RSA key pair, you must delete the
existing key pair. Otherwise, the retrieving operation will fail.
7.
Retrieving and displaying a
certificate
Optional.
Retrieve an existing certificate.
8.
Retrieving and displaying a
CRL
Optional.
Retrieve a CRL and display its contents.
Configuration procedure for automatic requests
Task Remarks
1.
Creating a PKI entity
Required.
Create a PKI entity and configure the identity information.
A certificate is the binding of a public key and the identity information of an
entity, where the DN shows the identity information of the entity. A CA
identifies a certificate applicant by a unique entity DN.
The DN settings of an entity need to be compliant with the CA certificate
issue policy, or the certificate request might be rejected. You must know the
policy to determine mandatory or optional entity parameters.
2.
Creating a PKI domain
Required.
Create a PKI domain and set the certificate request mode to
Auto
.
Before requesting a PKI certificate, an entity needs to be configured with
enrollment information, which is called a PKI domain.
A PKI domain is significant only to PKI and is intended as a reference for
other applications such as IKE and SSL.
Содержание HP 830 Series
Страница 37: ...25 Figure 18 Configuration complete ...
Страница 70: ...58 Figure 49 Displaying the rate settings of ports ...
Страница 78: ...66 Figure 56 Configuring the monitor port ...
Страница 82: ...70 Figure 59 Switching to the management level ...
Страница 87: ...75 Figure 64 Displaying port traffic statistics ...
Страница 167: ...155 Figure 154 Displaying the current voice VLAN information ...
Страница 304: ...292 Figure 280 Traceroute operation result ...
Страница 321: ...309 Request timed out Ping statistics for 10 0 0 1 Packets Sent 4 Received 0 Lost 4 100 loss ...
Страница 343: ...331 Figure 330 Ping operation summary ...
Страница 462: ...450 Figure 467 Configuring authorized IP ...