Configuration Guidelines; Configuration Procedure; Submitting A Pki Certificate Request - HP 6125G Configuration Manual

Security configuration guide
Hide thumbs Also See for 6125G:
Table of Contents

Advertisement

Configuration guidelines

Up to two PKI domains can be created on a switch.
The CA name is required only when you retrieve a CA certificate. It is not used when in local
certificate request.
The certificate request URL does not support domain name resolution.

Configuration procedure

To configure a PKI domain:
Step
1.
Enter system view.
2.
Create a PKI domain and
enter its view.
3.
Specify the trusted CA.
4.
Specify the entity for
certificate request.
5.
Specify the authority for
certificate request.
6.
Configure the certificate
request URL.
7.
Configure the polling interval
and attempt limit for querying
the certificate request status.
8.
Specify the LDAP server.
9.
Configure the fingerprint for
root certificate verification.

Submitting a PKI certificate request

When requesting a certificate, an entity introduces itself to the CA by providing its identity information
and public key, which will be the major components of the certificate. A certificate request can be
submitted to a CA in offline mode or online mode. In offline mode, a certificate request is submitted to
a CA by an "out-of-band" means such as phone, disk, or email.
Command
system-view
pki domain domain-name
ca identifier name
certificate request entity
entity-name
certificate request from { ca | ra }
certificate request url url-string
certificate request polling { count
count | interval minutes }
ldap-server ip ip-address [ port
port-number ] [ version
version-number ]
root-certificate fingerprint { md5 |
sha1 } string
161
Remarks
N/A
No PKI domain exists by default.
No trusted CA is specified by
default.
No entity is specified by default.
The specified entity must exist.
No authority is specified by
default.
No certificate request URL is
configured by default.
Optional.
The polling is executed for up to 50
times at the interval of 20 minutes
by default.
Optional.
No LDP server is specified by
default.
Required when the certificate
request mode is auto and optional
when the certificate request mode
is manual. In the latter case, if you
do not configure this command, the
fingerprint of the root certificate
must be verified manually.
No fingerprint is configured by
default.

Advertisement

Table of Contents
loading

This manual is also suitable for:

6125 blade switch series

Table of Contents