Displaying And Maintaining Pki; Pki Configuration Examples - HP VSR1000 Security Configuration Manual

Virtual services router
Table of Contents

Advertisement

Step
3.
(Optional.) Configure an
attribute rule for issuer name,
subject name, or alternative
subject name.
4.
Return to system view.
5.
Create a certificate access
control policy and enter its
view.
6.
Create a certificate access
control rule (or statement).

Displaying and maintaining PKI

Execute display commands in any view.
Task
Display the contents of a certificate.
Display certificate request status.
Display locally stored CRLs.
Display certificate attribute group
information.
Display certificate access control policy
information.

PKI configuration examples

You can use different software applications, such as Windows server, RSA Keon, and OpenCA, to act as
the CA server.
If you use Windows server or OpenCA, install the SCEP add-on for Windows server or enable SCEP for
OpenCA. In either case, when you configure a PKI domain, you must use the certificate request from ra
command to specify the RA to accept certificate requests for PKI entity enrollment to an RA.
If you use RSA Keon, the SCEP add-on is not required. When you configure a PKI domain, you must use
the certificate request from ca command to specify the CA to accept certificate requests for PKI entity
enrollment to a CA.
Command
attribute id { alt-subject-name
{ fqdn | ip } | { issuer-name |
subject-name } { dn | fqdn | ip } }
{ ctn | equ | nctn | nequ}
attribute-value
quit
pki certificate access-control-policy
policy-name
rule [ id ] { deny | permit }
group-name
Command
display pki certificate domain domain-name { ca | local | peer
[ serial serial-num ] }
display pki certificate request-status [ domain domain-name ]
display pki crl domain domain-name
display pki certificate attribute-group [ group-name ]
display pki certificate access-control-policy [ policy-name ]
147
Remarks
By default, not attribute rule is
configured.
N/A
By default, no certificate access
control policy exists.
By default, no statement is
configured, and all certificates can
pass the verification.
You can create multiple statements
for a certificate access control
policy.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents