Ike Negotiation With Rsa Digital Signature From A Windows 2003 Ca Server - HP VSR1000 Security Configuration Manual

Virtual services router
Table of Contents

Advertisement

IKE negotiation with RSA digital signature from a Windows
2003 CA server
Network requirements
Device A and Device B establish an IPsec tunnel to protect the traffic between Host A on subnet
10.1.1.0/24 and Host B on subnet 1.1.1.0/24.
Device A and Device use IKE to set up SAs, and the IKE proposal uses RSA digital signature for identity
authentication.
Device A and Device B use the same CA.
Figure 47 Network diagram
Configuring the CA server
In this example, a Windows 2003 server acts as the CA server. For information about how to configure
such a server, see
Configuring Device A
# Configure a PKI entity.
<DeviceA> system-view
[DeviceA] pki entity en
[DeviceA-pki-entity-en] ip 2.2.2.1
[DeviceA-pki-entity-en] common-name devicea
[DeviceA-pki-entity-en] quit
# Configure a PKI domain.
[DeviceA] pki domain 1
"Certificate request from a Windows 2003 CA
157
server."

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents