X509v3 extensions:
You can also use some other display commands (display pki certificate ca domain and display
pki crl domain commands) to display detailed information about the CA certificate and CRLs.
Certificate request from a Windows 2003 CA server
Network requirements
Configure PKI entity Router to request a local certificate from the CA server.
Figure 73 Network diagram
Configuring the CA server
1.
Install the certificate service suites:
a. Select Control Panel > Add or Remove Programs from the start menu.
b. Select Add/Remove Windows Components > Certificate Services.
c. Click Next to begin the installation.
2.
Install the SCEP add-on:
As a CA server running the Windows 2003 server does not support SCEP by default, you need
to install the SCEP add-on so that the router can register and obtain its certificate automatically.
After the SCEP add-on installation completes, a URL is displayed, which you need to configure
on the router as the URL of the server for certificate registration.
3.
Modify the certificate service attributes:
a. Select Control Panel > Administrative Tools > Certificate Authority from the start menu.
If the CA server and SCEP add-on have been installed successfully, there should be two
certificates issued by the CA to the RA.
b. Right-click the CA server in the navigation tree and select Properties > Policy Module.
c. Click Properties and select Follow the settings in the certificate template, if applicable.
Otherwise, automatically issue the certificate.
4.
Modify the Internet Information Services (IIS) attributes:
a. Select Control Panel > Administrative Tools > Internet Information Services (IIS)
Manager from the start menu.
b. Select Web Sites from the navigation tree.
c. Right-click Default Web Site and select Properties > Home Directory.
EA3CB6E0 B04649CE C9CDDD38 34015970
981E96D9 FF4F7B73 A5155649 E583AC61
D3A5C849 CBDE350D 2A1926B7 0AE5EF5E
D1D8B08A DBF16205 7C2A4011 05F11094
73EB0549 A65D9E74 0F2953F2 D4F0042F
19103439 3D4F9359 88FB59F3 8D4B2F6C
2B
Exponent: 65537 (0x10001)
X509v3 CRL Distribution Points:
URI:http://4.4.4.133:447/myca.crl
255
Need help?
Do you have a question about the FlexNetwork MSR Series and is the answer not in the manual?