271
Configuration guidelines
The following guidelines apply to certificate request for an entity in a PKI domain:
•
Make sure the device is time synchronized with the CA server. If the device is not time
synchronized with the CA server, the certificate request might fail because the certificate might
be considered to be outside of the validity period. For information about configuring the system
time, see
Fundamentals Configuration Guide
.
•
To request a new certificate for a PKI entity that already has a local certificate, perform the
following tasks:
a.
Use the
pki delete-certificate
command to delete the existing local certificate.
b.
Use the
public-key local create
to generate a new key pair. The new key pair will
automatically overwrite the old key pair in the domain.
c.
Submit a new certificate request.
•
To prevent a certificate from becoming unavailable after it is obtained, follow these guidelines:
{
Do not use the
public-key local create
command to create a key pair with the same name
as the name of the key pair contained in the certificate.
{
Do not use the
public-key local destroy
command to destroy the key pair contained in the
certificate.
•
A PKI domain can have local certificates using only one type of cryptographic algorithms (DSA,
ECDSA, or RSA). If DSA or ECDSA is used, a PKI domain can have only one local certificate. If
RSA is used, a PKI domain can have one local certificate for signature, and one local certificate
for encryption.
Configuring automatic certificate request
IMPORTANT:
The device does not support automatic certificate rollover. To avoid service interruptions, you must
manually submit a certificate renewal request before the current certificate expires.
In auto request mode, a PKI entity with no local certificates automatically submits a certificate
request to the CA when an application works with the PKI entity. For example, when IKE negotiation
uses a digital signature for identity authentication, but no local certificate is available, the entity
automatically submits a certificate request. It saves the certificate locally after obtaining the
certificate from the CA.
A CA certificate must be present before you request a local certificate. If no CA certificate exists in the
PKI domain, the PKI entity automatically obtains a CA certificate before sending a certificate request.
To configure automatic certificate request:
Step Command Remarks
1.
Enter system view.
system-view
N/A
2.
Enter PKI domain view.
pki domain
domain-name
N/A
3.
Set the certificate request
mode to auto.
certificate request mode auto
[
password
{
cipher
|
simple
}
string
]
By default, the manual
request mode applies.
In auto request mode, set
a password for certificate
revocation as required by
the CA policy.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...