
# Configure the trusted CA, bound entity, enrollment URL, and root certificate fingerprint.
[Huawei]
pki realm test
[Huawei-pki-realm-test]
ca id ca_root
[Huawei-pki-realm-test]
entity user01
[Huawei-pki-realm-test]
enrollment-url http://10.137.145.158:8080/certsrv/mscep/
mscep.dll ra
[Huawei-pki-realm-test]
fingerprint sha1 7A34D94624B1C1BCBF6D763C4A67035D5B578EAF
[Huawei-pki-realm-test]
quit
Step 4
Enroll the certificate manually.
[Huawei]
pki enroll-certificate test
Create a challenge password. You will need to verbally provide this password to
the CA Administrator in order to revoke your certificate.
For security reasons your password will not be saved in the configuration. Plea
se make a note of it.
Choice no password ,please enter the enter-key.
Please enter Password:
Start certificate enrollment ...
Certificate is enrolling now,It will take a few minutes or more.
Please waiting...
The certificate enroll successful.
You will be prompted to enter the password during certificate enrollment. If you do not have a
password, press
Enter
.
Step 5
Verify the configuration.
After the preceding configurations are complete, the CA issues a certificate to the PKI entity.
In the certificate information, the
issued to
field value is the entity common name
hello
.
Run the
display pki certificate
{
local
|
ca
}
pki-realm-name
[
verbose
] command on the PKI
entity to view the certificate.
<Huawei>
display pki certificate local test
Certificate
Status : Available
Version: 3
Serial Number:
19 36 41 af 00 00 00 00 02 ba
Subject:
C=CN
ST=jiangsu
O=huawei
OU=info
CN=hello
Associated Pki Realm : test
Total Number: 1
----End
Configuration Files
#
pki entity user01
country CN
state jiangsu
organization huawei
organization-unit info
common-name hello
#
pki realm test
ca id ca_root
enrollment-url http://10.137.145.158:8080/certsrv/mscep/mscep.dll ra
entity user01
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
12 PKI Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
253