
Table 12-1
Data plan
Item
Data
PKI entity
PKI entity name: user01
l
Entity's common name: hello
l
Entity's country code: CN
l
Entity's province name: jiangsu
l
Entity's organization name: huawei
l
Entity's department name: info
PKI domain name
PKI domain name: test
l
Trusted CA name: ca_root
l
Certificate's enrollment URL: http://
10.137.145.158:8080/certsrv/mscep/mscep.dll
l
Bound PKI entity name: user01
l
CA's fingerprint algorithm: secure hash algorithm
(SHA)
Fingerprint:
17A34D94624B1C1BCBF6D763C4A67035D5B5
78EAF
Configuration Roadmap
1.
Configure a PKI entity to identify a certificate applicant.
2.
Configure a PKI domain and specify identity information required for certificate
enrollment, including the trusted CA name, bound entity name, enrollment URL, and root
certificate fingerprint.
3.
Obtain a local certificate manually.
Procedure
Step 1
Configure interface IP addresses and routes to enable the PKI entity and CA to communicate.
Step 2
Configure a PKI entity to identify a certificate applicant.
# Configure a PKI entity user01.
<Huawei>
system-view
[Huawei]
pki entity user01
[Huawei-pki-entity-user01]
common-name hello
[Huawei-pki-entity-user01]
country cn
[Huawei-pki-entity-user01]
state jiangsu
[Huawei-pki-entity-user01]
organization huawei
[Huawei-pki-entity-user01]
organization-unit info
[Huawei-pki-entity-user01]
quit
Step 3
Configure a PKI domain and specify the identity information required for certificate enrollment
in the PKI domain.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
12 PKI Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
252