HP MSR2000 Configuration Manual page 137

Hide thumbs Also See for MSR2000:
Table of Contents

Advertisement

Figure 37 Network diagram
Configuration procedure
1.
Export the certificate on Device A to specified files:
# Export the CA certificate to a file named pkicachain.pem in PEM format.
<DeviceA> system-view
[DeviceA] pki export domain exportdomain pem ca filename pkicachain.pem
# Export the local certificate to a file named pkilocal.pem in PEM format, and use 3DES_CBC to
encrypt the private key with the password 111111.
[DeviceA] pki export domain exportdomain pem local 3des-cbc 111111 filename
pkilocal.pem
After the above operations, the system generates three certificate files in PEM format. One is the
CA certificate file pkicachain.pem, one is the local certificate file pkilocal.pem-signature, which
contains the private key for signature, and one is the local certificate file pkilocal.pem-encryption,
which contains the private key for encryption.
# Display the local certificate file pkilocal.pem-signature.
[DeviceA] quit
<DeviceA> more pkicachain.pem-sign
Bag Attributes
friendlyName:
localKeyID: 90 C6 DC 1D 20 49 4F 24 70 F5 17 17 20 2B 9E AC 20 F3 99 89
subject=/C=CN/O=OpenCA Labs/OU=Users/CN=subsign 11
issuer=/C=CN/L=shangdi/ST=beijing/O=OpenCA Labs/OU=docm/CN=subca1
-----BEGIN CERTIFICATE-----
MIIEgjCCA2qgAwIBAgILAJgsebpejZc5UwAwDQYJKoZIhvcNAQELBQAwZjELMAkG
...
-----END CERTIFICATE-----
Bag Attributes
friendlyName:
localKeyID: 90 C6 DC 1D 20 49 4F 24 70 F5 17 17 20 2B 9E AC 20 F3 99 89
Key Attributes: <No Attributes>
-----BEGIN ENCRYPTED PRIVATE KEY-----
MIICxjBABgkqhkiG9w0BBQ0wMzAbBgkqhkiG9w0BBQwwDgQIZtjSjfslJCoCAggA
...
-----END ENCRYPTED PRIVATE KEY-----
# # Display the local certificate file pkilocal.pem-encryption.
<DeviceA> more pkicachain.pem-encr
126

Advertisement

Table of Contents
loading

This manual is also suitable for:

Msr3000Msr4000

Table of Contents