HP VSR1000 Security Configuration Manual page 159

Virtual services router
Table of Contents

Advertisement

# Specify the PKI entity name as aaa.
[Device-pki-domain-torsa] certificate request entity aaa
# Specify the URL of the CRL repository.
[Device-pki-domain-torsa] crl url http://4.4.4.133:447/myca.crl
# Specify the RSA key pair with the purpose general, the name abc, and the length 1024 bits.
[Device-pki-domain-torsa] public-key rsa general name abc length 1024
[Device-pki-domain-torsa] quit
4.
Generate a local RSA key pair.
[Device] public-key local create rsa name abc
The range of public key size is (512 ~ 2048).
If the key modulus is greater than 512,it will take a few minutes.
Press CTRL+C to abort.
Input the modulus length [default = 1024]:
Generating Keys...
..........................++++++
.....................................++++++
Create the key pair successfully.
5.
Request a local certificate:
# Obtain the CA certificate and save it locally.
[Device] pki retrieve-certificate domain torsa ca
The trusted CA's finger print is:
MD5
SHA1 fingerprint: 77F9 A077 2FB8 088C 550B A33C 2410 D354 23B2 73A8
Is the finger print correct?(Y/N):y
# Submit a certificate request manually. When an RSA Keon CA server is used, a password must
be specified.
[Device] pki request-certificate domain torsa password 1111
Start to request the general certificate ...
......
Request certificate of domain torsa successfully
Verifying the configuration
# After obtaining the local certificate, display information about the certificate.
[Device] display pki certificate domain torsa local
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
Signature Algorithm: sha1WithRSAEncryption
Issuer:
Validity
fingerprint:EDE9 0394 A273 B61A F1B3 0072 A0B1 F9AB
9A96A48F 9A509FD7 05FFF4DF 104AD094
C=cn
O=org
OU=test
CN=myca
Not Before: Aug 24 09:06:29 2013 GMT
149

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents