Configuration Procedure; Verifying Pki Certificates; Verifying Certificates With Crl Checking - HP FlexFabric 5930 Series Security Configuration Manual

Hide thumbs Also See for FlexFabric 5930 Series:
Table of Contents

Advertisement

Configuration procedure

To obtain certificates:
Step
1.
Enter system view.
2.
Import or obtain certificates.

Verifying PKI certificates

Every time a certificate is requested or obtained, or used by an application, it is automatically verified.
If the certificate expires, is not issued by a trusted CA, or is revoked, the certificate is not used.
You can also manually verify a certificate. If it is revoked, the certificate cannot be requested or obtained.

Verifying certificates with CRL checking

CRL checking checks whether a certificate is in the CRL. If yes, the certificate has been revoked and its
home entity is not trusted.
To use CRL checking, a CRL must be obtained from a CRL repository. The device selects a CRL repository
in the following order: CRL repository specified in the PKI domain, the CRL repository in the local
certificates, the CRL repository in the CA certificate, and the CRL obtained through SCEP.
To use SCEP to obtain the CRL, the CA certificate and the local certificates must be present.
To verify certificates with CRL checking:
Step
1.
Enter system view.
2.
Enter PKI domain view.
3.
(Optional.) Specify the URL
of the CRL repository.
4.
Enable CRL checking.
5.
Return to system view.
6.
Obtain the CA certificate.
Command
system-view
Import certificates in offline mode:
pki import domain domain-name { der { ca |
local | peer } filename filename | p12 local
filename filename | pem { ca | local | peer }
[ filename filename ] }
Obtain certificates in online mode:
pki retrieve-certificate domain
domain-name { ca | local | peer
entity-name }
Command
system-view
pki domain domain-name
crl url url-string [ vpn-instance
vpn-instance-name ]
crl check enable
quit
See
"Obtaining
certificates."
79
Remarks
N/A
The pki
retrieve-certificate
command is not saved
in the configuration
file.
Remarks
N/A
N/A
By default, the URL of the CRL
repository is not specified.
By default, CRL checking is enabled.
N/A
N/A

Advertisement

Table of Contents
loading

Table of Contents