Huawei AR1200-S Configuration Manual page 240

Enterprise routers
Hide thumbs Also See for AR1200-S:
Table of Contents

Advertisement

Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
Procedure
Step 1 Configure a PKI entity and a PKI domain.
# Configure a PKI entity.
<Huawei> system-view
[Huawei] sysname Router
[Router] pki entity users
[Router-pki-entity-users] common-name hello
[Router-pki-entity-users] country cn
[Router-pki-entity-users] state jiangsu
[Router-pki-entity-users] organization huawei
[Router-pki-entity-users] organization-unit info
[Router-pki-entity-users] quit
# Configure a PKI domain, and enable the automatic certificate enrollment and update function.
[Router] pki realm users
[Router-pki-realm-users] entity users
[Router-pki-realm-users] ca id ca_root
[Router-pki-realm-users] enrollment-url http://11.137.145.158:8080/certsrv/mscep/
mscep.dll ra
[Router-pki-realm-users] fingerprint sha1 7bb05ada0482273388ed4ec228d79f77309ea3f4
[Router-pki-realm-users] auto-enroll regenerate
[Router-pki-realm-users] quit
Step 2 Configure a server SSL policy sslserver.
# Create a server SSL policy and specify PKI domain users in the policy. This allows the
Router to obtain a digital certificate from the CA specified in the PKI domain.
[Router] ssl policy sslserver type server
[Router-ssl-policy-sslserver] pki-realm users
# Set the maximum number of sessions that can be saved and the timeout period of a session.
[Router-ssl-policy-sslserver] session cachesize 40 timeout 7200
[Router-ssl-policy-sslserver] quit
Step 3 Configure the Router as an HTTPS server.
# Apply the SSL policy sslserver to the HTTPS service.
[Router] http secure-server ssl-policy sslserver
# Enable the HTTPS server function on the Router.
[Router] http secure-server enable
# Configure the port number of the HTTPS service.
[Router] http secure-server port 1278
Step 4 Verify the configuration.
# Run the display ssl policy command to view the configuration of the SSL policy sslserver.
<Router> display ssl policy sslserver
Issue 02 (2012-03-30)
NOTE
If the entity name and entity common name are not set to the Router's IP address 11.1.1.1, the system will
display a message indicating that the certificate is invalid when the client opens a website. This does not
affect HTTPS application.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
11 SSL Configuration
226

Advertisement

Table of Contents
loading

Table of Contents