Requesting A Certificate From A Ca Server Running Windows 2003 Server - HP A6600 Configuration Manual

Hide thumbs Also See for A6600:
Table of Contents

Advertisement

Requesting a certificate from a CA server running Windows
2003 Server
Network requirements
Configure PKI entity Router to request a local certificate from the CA server.
Figure 87 Request a certificate from a CA server running Windows 2003 server
Configuration procedure
Configure the CA server.
1.
Install the certificate service suites.
From the start menu, select Control Panel > Add or Remove Programs, and then select Add/Remove
Windows Components > Certificate Services and click Next to begin the installation.
Install the SCEP add-on.
Because a CA server running the Windows 2003 server does not support SCEP by default, you must
install the SCEP add-on so that the router can register and obtain its certificate automatically. After the
SCEP add-on installation completes, a URL is displayed, which you must configure on the router as the
URL of the server for certificate registration.
Modify the certificate service attributes.
From the start menu, select Control Panel > Administrative Tools > Certificate Authority. If the CA server
and SCEP add-on have been installed successfully, there should be two certificates issued by the CA to
the RA. Right-click the CA server in the navigation tree and select Properties > Policy Module. Click
Properties and then select Follow the settings in the certificate template, if applicable. Otherwise,
automatically issue the certificate.
Modify the IIS attributes.
From the start menu, select Control Panel > Administrative Tools > Internet Information Services (IIS)
Manager and then select Web Sites from the navigation tree. Right-click Default Web Site and select
Properties > Home Directory. Specify the path for certificate service in the Local path text box. To avoid
conflict with existing services, specify an available port number as the TCP port number of the default
website.
After completing the configuration, check that the system clock of the router is synchronous to that of the
CA server, ensuring that the router can request a certificate normally.
Configure the router.
2.
Configure the entity DN.
# Configure the entity name as aaa and the common name as router.
<Router> system-view
[Router] pki entity aaa
[Router-pki-entity-aaa] common-name router
234

Advertisement

Table of Contents
loading

Table of Contents