Retrieving A Certificate Manually; Configuring Pki Certificate Validation - 3Com MSR 50 Series Configuration Manual

3com msr 30-16: software guide
Hide thumbs Also See for MSR 50 Series:
Table of Contents

Advertisement

Retrieving a
Certificate Manually
Configuring PKI
Certificate Validation
The pki request-certificate domain configuration will not be saved in the
configuration file.
You can download an existing CA certificate or local certificate from the CA server
and save it locally. To do so, you can use two ways: online and offline. In offline
mode, you need to retrieve a certificate by an out-of-band means like FTP, disk,
e-mail and then import it into the local PKI system.
Certificate retrieval serves two purposes:
Locally store the certificates associated with the local security domain for
improved query efficiency and reduced query count;
Prepare for certificate validation.
You must configure the LDAP server before retrieving a local certificate.
Follow these steps to retrieve a certificate manually:
To do...
Enter system view
Retrieve a certificate
manually
c
CAUTION:
If a PKI domain has already a CA certificate, you cannot retrieve another CA
certificate for it. This is in order to avoid inconsistency between the certificate
and enrollment information due to related configuration changes. To retrieve a
new CA certificate, use the pki delete-certificate command to delete the
existing CA certificate and local certificate first.
The pki retrieval-certificate configuration will not be saved in the
configuration file.
A certificate needs to be validated before being used. Validating a certificate is to
check that the certificate is signed by the CA and that the certificate has neither
expired nor been revoked.
Before validating a certificate, you need to retrieve the CA certificate.
You can specify whether CRL checking is required in certificate validation. If you
enable CRL checking, CRLs will be used in validation of a certificate.
Configuring CRL-checking-enabled PKI certificate validation
Follow these steps to configure CRL-checking-enabled PKI certificate validation:
Use the command...
system-view
Online
pki retrieval-certificate
{ ca | local } domain
domain-name
Offline
pki import-certificate
{ ca | local } domain
domain-name { der | p12 |
pem } [ filename
filename ]

Retrieving a Certificate Manually

Remarks
-
Required
Use either command
1837

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents