Fips Compliance; Pki Configuration Task List; Configuring A Pki Entity - HP MSR Series Configuration Manual

Hpe flexnetwork msr router series
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

FIPS compliance

The device supports the FIPS mode that complies with NIST FIPS 140-2 requirements. Support for
features, commands, and parameters might differ in FIPS mode (see
non-FIPS mode.

PKI configuration task list

Tasks at a glance
(Required.)
(Required.)
(Required.)
Configuring automatic certificate request
Manually requesting a certificate
(Optional.)
Aborting a certificate request
(Optional.)
Obtaining certificates
(Optional.)
Verifying PKI certificates
(Optional.)
Specifying the storage path for the certificates and CRLs
(Optional.)
Exporting certificates
(Optional.)
Removing a certificate
(Optional.)
Configuring a certificate-based access control policy

Configuring a PKI entity

A certificate applicant uses an entity to provide its identity information to a CA. A valid PKI entity must
include one or more of following identity categories:
Distinguished name (DN) of the entity, which further includes the common name, county code,
locality, organization, unit in the organization, and state. If you configure the DN for an entity, a
common name is required.
FQDN of the entity.
IP address of the entity.
Whether the categories are required or optional depends on the CA policy. Follow the CA policy to
configure the entity settings. For example, if the CA policy requires the entity DN, but you configure
only the IP address, the CA rejects the certificate request from the entity.
The SCEP add-on on the Windows 2000 CA server has restrictions on the data length of a certificate
request. If a request from a PKI entity exceeds the data length limit, the CA server does not respond
to the certificate request. In this case, you can use an out-of-band means to submit the request.
Other types of CA servers, such as RSA servers and OpenCA servers, do not have such restrictions.
To configure a PKI entity:
Step
1.
Enter system view.
Configuring a PKI entity
Configuring a PKI domain
Requesting a
certificate:
Command
system-view
Remarks
N/A
248
"Configuring
FIPS") and

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents