Submitting A Certificate Request In Auto Mode; Submitting A Certificate Request In Manual Mode - HP 5120 EI Switch Series Configuration Manual

Hide thumbs Also See for 5120 EI Switch Series:
Table of Contents

Advertisement

submitted to a CA in an online mode or an offline mode. In offline mode, a certificate request is
submitted to a CA by an ―out-of-band‖ means such as phone, disk, or email.
An online certificate request can be submitted in manual mode or auto mode.

Submitting a certificate request in auto mode

In auto mode, an entity automatically requests a certificate from the CA server if it has no local certificate
for an application working with PKI, and then retrieves the certificate and saves the certificate locally.
Before requesting a certificate, if the PKI domain does not have the CA certificate yet, the entity
automatically retrieves the CA certificate.
Follow these steps to configure an entity to submit a certificate request in auto mode:
To do...
Enter system view
Enter PKI domain view
Set the certificate request mode to
auto
IMPORTANT:
In auto mode, an entity does not automatically re-request a certificate to replace a certificate that is
expiring or has expired. After the certificate expires, the service using the certificate might be
interrupted.

Submitting a certificate request in manual mode

In manual mode, you manually submit a certificate request for an entity. Before submitting a certificate
request, you must ensure that an RSA key pair has been generated and the CA certificate has been
retrieved and saved locally.
The CA certificate is required to verify the authenticity and validity of a local certificate. The public key of
the key pair is an important part of the request information and will be transferred to the CA along with
some other information. For more information about RSA key pair configuration, see the Security
Configuration Guide.
Follow these steps to submit a certificate request in manual mode:
To do...
Enter system view
Enter PKI domain view
Set the certificate request mode to
manual
Return to system view
Retrieve a CA certificate manually
Use the command...
system-view
pki domain domain-name
certificate request mode auto [
key-length key-length | password
{ cipher | simple } password ] *
Use the command...
system-view
pki domain domain-name
certificate request mode manual
quit
See
―Retrieving a certificate
manually―
193
Remarks
Required
Manual by default
Remarks
Optional
Manual by default
―Required

Advertisement

Table of Contents
loading

Table of Contents