Verifying Pki Certificates; Verifying Pki Certificates With Crl Checking - HP 6600 Security Configuration Manual

Table of Contents

Advertisement

If a PKI domain already has a CA certificate, you cannot obtain another CA certificate for it. This
restriction helps avoid inconsistency between the certificate and registration information resulted from
configuration changes. To obtain a new CA certificate, use the pki delete-certificate command to delete
the existing CA certificate and the local certificate first.
Be sure that the device system time falls in the validity period of the certificate so that the certificate is
valid.
To obtain a certificate manually:
Step
1.
Enter system view.
2.
Obtain a certificate
manually

Verifying PKI certificates

A certificate needs to be verified before being used. Verifying a certificate will check that the certificate
is signed by the CA and that the certificate has neither expired nor been revoked.
You can specify whether CRL checking is required in certificate verification. If you enable CRL checking,
CRLs will be used in verification of a certificate. In this case, be sure to obtain the CA certificate and CRLs
to the local device before the certificate verification. If you disable CRL checking, you only need to obtain
the CA certificate.
The CRL update period defines the interval at which the entity downloads CRLs from the CRL server. The
CRL update period setting manually configured on the device is prior to that carried in the CRLs.

Verifying PKI certificates with CRL checking

Step
1.
Enter system view.
2.
Enter PKI domain view.
3.
Specify the URL of the CRL
distribution point.
4.
Set the CRL update period.
5.
Enable CRL checking.
Command
system-view
In online mode:
pki retrieval-certificate { ca | local } domain
domain-name
In offline mode:
pki import-certificate { ca | local } domain
domain-name { der | p12 | pem } [ filename
filename ]
Command
system-view
pki domain domain-name
crl url url-string
crl update-period hours
crl check enable
234
Remarks
N/A
Use either command.
The pki
retrieval-certificate
configuration is not
saved in the
configuration file.
Remarks
N/A
N/A
Optional.
No CRL distribution point URL is
specified by default.
Optional.
By default, the CRL update period
depends on the next update field in
the CRL file.
Optional.
Enabled by default.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Hsr6600

Table of Contents