Submitting A Pki Certificate Request - HP 5120 EI Switch Series Configuration Manual

Hide thumbs Also See for 5120 EI Switch Series:
Table of Contents

Advertisement

Follow these steps to configure a PKI domain:
To do...
Enter system view
Create a PKI domain and enter its
view
Specify the trusted CA
Specify the entity for certificate
request
Specify the authority for certificate
request
Configure the URL for certificate
request
Configure the polling interval and
attempt limit for querying the
certificate request status
Specify the LDAP server
Configure the fingerprint for root
certificate verification
NOTE:
Up to two PKI domains can be created on a device.
The CA name is required only when you retrieve a CA certificate. It is not used when in local certificate request.
The certificate request URL does not support domain name resolution.

Submitting a PKI certificate request

When requesting a certificate, an entity introduces itself to the CA by providing its identity information
and public key, which will be the major components of the certificate. A certificate request can be
Use the command...
system-view
pki domain domain-name
ca identifier name
certificate request entity entity-
name
certificate request from { ca | ra }
certificate request url url-string
certificate request polling { count
count | interval minutes }
ldap-server ip ip-address [ port
port-number ] [ version version-
number ]
root-certificate fingerprint { md5 |
sha1 } string
192
Remarks
Required
No PKI domain exists by default.
Required
No trusted CA is specified by
default.
Required
No entity is specified by default.
The specified entity must exist.
Required
No authority is specified by
default.
Required
No certificate request URL is
configured by default.
Optional
The polling is executed for up to
50 times at the interval of 20
minutes by default.
Optional
No LDP server is specified by
default.
Required when the certificate
request mode is auto and optional
when the certificate request mode
is manual. In the latter case, if you
do not configure this command,
the fingerprint of the root
certificate must be verified
manually.
No fingerprint is configured by
default.

Advertisement

Table of Contents
loading

Table of Contents