Submitting A Pki Certificate Request; Submitting A Certificate Request In Auto Mode; Submitting A Certificate Request In Manual Mode - HP A6600 Configuration Manual

Hide thumbs Also See for A6600:
Table of Contents

Advertisement

Submitting a PKI certificate request

When requesting a certificate, an entity introduces itself to the CA by providing its identity information
and public key, which are the major components of the certificate. A certificate request can be submitted
to a CA in offline mode or online mode. In offline mode, a certificate request is submitted to a CA by an
out-of-band means such as phone, disk, or email.
Online certificate requests fall into manual mode and auto mode.

Submitting a certificate request in auto mode

In auto mode, an entity automatically requests a certificate from the CA server if it has no local
certificate for an application working with PKI. For example, when PKI certificate authentication is used,
if no local certificate is available during IKE negotiation, the entity automatically requests one.
To configure an entity to submit a certificate request in auto mode:
To do...
1.
Enter system view.
2.
Enter PKI domain view.
3.
Set the certificate request
mode to auto.
NOTE:
If a certificate will expire or has expired, the entity does not initiate a re-request automatically, and the
service using the certificate might be interrupted. To have a new local certificate, request one manually.

Submitting a certificate request in manual mode

In manual mode, you must retrieve a CA certificate, generate a local RSA key pair, and submit a local
certificate request for an entity.
The goal of retrieving a CA certificate verifies the authenticity and validity of a local certificate.
Generating an RSA key pair is an important step in certificate request. The key pair includes a public
key and a private key. The private key is kept by the user. The public key is transferred to the CA along
with some other information. For more information about RSA and DSA key pair configuration, see
"Configuring public
Command...
system-view
pki domain domain-name
certificate request mode auto [
key-length key-length | password
{ cipher | simple } password ] *
keys."
Remarks
Required
Manual by default
225

Advertisement

Table of Contents
loading

Table of Contents