
mscep.dll ra
[Router-pki-realm-admin]
fingerprint sha1 7A34D94624B1C1BCBF6D763C4A67035D5B578EAF
[Router-pki-realm-admin]
quit
# Enroll the certificate manually.
[Router]
pki enroll-certificate admin
Info: Start certificate enrollment ...
Create a challenge password. You will need to verbally provide this password to
the CA Administrator in order to revoke your certificate.
For security reasons your password will not be saved in the configuration. Plea
se make a note of it.
Choice no password ,please enter the enter-key.
Please enter Password:
Start certificate enrollment ...
Cert enrolling now,It will take a few minutes or more.
Please waiting...
[Router]
The certificate enroll successful.
NOTE
You will be prompted to enter the password during certificate enrollment. If you do not have a password, press
Enter
.
Step 2
Configure a server SSL policy.
# Create a server SSL policy and specify PKI domain
admin
in the policy. This allows the
Router to obtain a digital certificate from the CA specified in the PKI domain.
[Router]
ssl policy adminserver type server
[Router-ssl-policy-adminserver]
pki-realm admin
# Set the maximum number of sessions that can be saved and the timeout period of a saved
session.
[Router-ssl-policy-adminserver]
session cachesize 40 timeout 7200
[Router-ssl-policy-adminserver]
quit
Step 3
Configure the Router as an HTTPS server.
# Apply the SSL policy
adminserver
to the HTTPS service.
[Router]
http secure-server ssl-policy adminserver
# Configure the port number of the HTTPS service.
[Router]
http secure-server port 1278
# Enable the HTTPS server function on the Router.
[Router]
http secure-server enable
Step 4
Verify the configuration.
# Run the
display ssl policy policy-name
command to view the configuration of the SSL policy
adminserver
.
<Router>
display ssl policy adminserver
------------------------------------------------------------------------------
Policy name :
adminserver
Policy ID : 1
Policy type : Server
Cache number : 40
Time out(second) : 7200
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
2 HTTPS Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
40