234
Requesting a certificate from a CA server running Windows
2003 Server
Network requirements
Configure PKI entity Router to request a local certificate from the CA server.
Figure 87
Request a certificate from a CA server running Windows 2003 server
Configuration procedure
1.
Configure the CA server.
•
Install the certificate service suites.
From the start menu, select
Control Panel
>
Add or Remove Programs
, and then select
Add/Remove
Windows Components
>
Certificate Services
and click
Next
to begin the installation.
•
Install the SCEP add-on.
Because a CA server running the Windows 2003 server does not support SCEP by default, you must
install the SCEP add-on so that the router can register and obtain its certificate automatically. After the
SCEP add-on installation completes, a URL is displayed, which you must configure on the router as the
URL of the server for certificate registration.
•
Modify the certificate service attributes.
From the start menu, select
Control Panel
>
Administrative Tools
>
Certificate Authority
. If the CA server
and SCEP add-on have been installed successfully, there should be two certificates issued by the CA to
the RA. Right-click the CA server in the navigation tree and select
Properties
>
Policy Module
. Click
Properties
and then select
Follow the settings in the certificate template, if applicable. Otherwise,
automatically issue the certificate
.
•
Modify the IIS attributes.
From the start menu, select
Control Panel
>
Administrative Tools
>
Internet Information Services (IIS)
Manager
and then select
Web Sites
from the navigation tree. Right-click
Default Web Site
and select
Properties
>
Home Directory
. Specify the path for certificate service in the
Local path
text box. To avoid
conflict with existing services, specify an available port number as the TCP port number of the default
website.
After completing the configuration, check that the system clock of the router is synchronous to that of the
CA server, ensuring that the router can request a certificate normally.
2.
Configure the router.
•
Configure the entity DN.
# Configure the entity name as
aaa
and the common name as
router
.
<Router> system-view
[Router] pki entity aaa
[Router-pki-entity-aaa] common-name router