273
•
In offline mode, obtain the certificates by an out-of-band means like FTP, disk, or email, and
then import them locally. Use this mode when the CRL repository is not specified, the CA server
does not support SCEP, or the CA server generates the key pair for the certificates.
•
In online mode, you can obtain the CA certificate through SCEP and obtain local certificates or
peer certificates through LDAP.
Configuration prerequisites
To obtain local or peer certificates in online mode, specify the LDAP server for the PKI domain.
To import local or peer certificates in offline mode, perform the following tasks:
•
Use FTP or TFTP to upload the certificate files to the storage media of the device. If FTP or
TFTP is not available, display and copy the contents of a certificate to a file on the device. Make
sure the certificate is in PEM format because only certificates in PEM format can be imported.
•
To import a certificate, a CA certificate chain must exist in the PKI domain, or be contained in the
certificate. If the CA certificate chain is not available, obtain it before importing the certificate.
Configuration guidelines
•
To import a local certificate containing an encrypted key pair, you must provide the challenge
password. Contact the CA administrator to obtain the password.
•
If a CA certificate already exists locally, you cannot obtain it again in online mode. If you want to
obtain a new one, use the
pki delete-certificate
command to remove the existing CA certificate
and local certificates first.
•
If local or peer certificates already exist, you can obtain new local or peer certificates to
overwrite the existing ones. If RSA is used, a PKI domain can have two local certificates, one for
signature and the other for encryption.
•
If CRL checking is enabled, obtaining a certificate triggers CRL checking. If the certificate to be
obtained has been revoked, the certificate cannot be obtained.
•
The device compares the validity period of a certificate with the local system time to determine
whether the certificate is valid. Make sure the system time of the device is synchronized with the
CA server.
Configuration procedure
To obtain certificates:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Obtain certificates.
•
Import certificates in offline mode:
pki import domain domain-name
{
der
{
ca
|
local
|
peer
}
filename filename
|
p12 local filename filename
|
pem
{
ca
|
local
|
peer
} [
filename filename
] }
•
Obtain certificates in online mode:
pki retrieve-certificate
domain
domain-name
{
ca
|
local
|
peer
entity-name
}
The
pki
retrieve-certificate
command is not saved
in the configuration
file.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...