HP MSR2000 Configuration Manual page 128

Hide thumbs Also See for MSR2000:
Table of Contents

Advertisement

Figure 34 Network diagram
Configuring the CA server
1.
Install the certificate service component:
a.
Select Control Panel > Add or Remove Programs from the start menu.
b.
Select Add/Remove Windows Components > Certificate Services.
c.
Click Next to begin the installation.
d.
Set the CA name. In this example, set the CA name to myca.
2.
Install the SCEP add-on:
The Windows 2003 server does not support SCEP by default. Install the SCEP add-on on the server
so that the device can automatically register and obtain its certificate from the server. After the
SCEP add-on installation completes, you will see a URL. Use the URL to configure it on the device
as the URL of the registration server for certificate request.
3.
Modify the certificate service attributes:
a.
Select Control Panel > Administrative Tools > Certificate Authority from the start menu.
If the certificate service component and SCEP add-on have been installed successfully, there
should be two certificates issued by the CA to the RA.
b.
Right-click the CA server in the navigation tree and select Properties > Policy Module.
c.
Click Properties and then select Follow the settings in the certificate template, if applicable.
Otherwise, automatically issue the certificate.
4.
Modify the Internet information services attributes:
a.
Select Control Panel > Administrative Tools > Internet Information Services (IIS) Manager from
the start menu.
b.
Select Web Sites from the navigation tree.
c.
Right-click Default Web Site and select Properties > Home Directory.
d.
Specify the path for certificate service in the Local path box.
e.
Specify an available port number as the TCP port number for the default website to avoid
conflict with existing services. In this example, port 8080 is used.
Configuring the device
1.
Synchronize the system time of the device with the CA server, so that the device can correctly
request a certificate.
2.
Create an entity named aaa with the common name as test.
<Device> system-view
[Device] pki entity aaa
[Device-pki-entity-aaa] common-name test
[Device-pki-entity-aaa] quit
3.
Configure a PKI domain:
# Create a PKI domain named winserver and enter its view.
117

Advertisement

Table of Contents
loading

This manual is also suitable for:

Msr3000Msr4000

Table of Contents