
Table 12-2
Data plan of RouterA
Item
Data
PKI entity
PKI entity name: routera
l
Entity's common name: helloa
l
Entity's country code: CN
l
Entity's province name: jiangsu
l
Entity's organization name: huawei
l
Entity's department name: info
PKI domain name
PKI domain name: test
l
Trusted CA name: ca_root
l
Certificate's enrollment URL: http://
10.137.145.158:8080/certsrv/mscep/mscep.dll
l
Bound entity name: routera
l
CA's fingerprint algorithm: secure hash algorithm (SHA)
Fingerprint:
17A34D94624B1C1BCBF6D763C4A67035D5B578E
AF
IKE proposal
l
Encryption algorithm: 3DES-CBC
l
Authentication algorithm: SHA1
l
Authentication mode: Rivest, Shamir, and Adelman
(RSA) signature
IKE peer
l
IKE peer name: routera
l
Local peer's ID type: IP address
l
Local IP address: 1.1.1.1
l
Remote IP address: 2.2.2.1
l
Negotiation mode: main
IPSec proposal
l
Transport protocol: ESP
l
Authentication algorithm: SHA1
l
Encryption algorithm: 3DES
l
Encapsulation mode: tunnel
IPSec policy
Security association (SA) triggering mode: automatic
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
12 PKI Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
255