Requesting A Certificate From A Ca Running Windows 2003 Server - HP 5120 SI Series Security Configuration Manual

Hide thumbs Also See for 5120 SI Series:
Table of Contents

Advertisement

You can also use some other display commands—display pki certificate ca domain and display pki crl
domain commands—to view detailed information about the CA certificate and CRLs. For more
information about the commands, see the Security Command Reference.
Requesting a certificate from a CA running Windows 2003
Server
NOTE:
The CA server runs the Windows 2003 server in this configuration example.
Network requirements
Configure PKI entity Switch to request a local certificate from the CA server.
Figure 78 Request a certificate from a CA running Windows 2003 server
Configuration procedure
1.
Configure the CA server
Install the certificate service suites
From the start menu, select Control Panel > Add or Remove Programs, and then select
Add/Remove Windows Components > Certificate Services and click Next to begin the
installation.
Install the SCEP add-on
As a CA server running the Windows 2003 server does not support SCEP by default, you need
to install the SCEP add-on so that the switch can register and obtain its certificate automatically.
After the SCEP add-on installation completes, a URL is displayed, which you need to configure
on the switch as the URL of the server for certificate registration.
Modify the certificate service attributes
From the start menu, select Control Panel > Administrative Tools > Certificate Authority. If the
CA server and SCEP add-on have been installed successfully, there should be two certificates
issued by the CA to the RA. Right-click on the CA server in the navigation tree and select
Properties > Policy Module. Click Properties and then select Follow the settings in the certificate
template, if applicable. Otherwise, automatically issue the certificate.
Modify the Internet Information Services (IIS) attributes
From the start menu, select Control Panel > Administrative Tools > Internet Information Services
(IIS) Manager and then select Web Sites from the navigation tree. Right-click on Default Web
Site and select Properties > Home Directory. Specify the path for certificate service in the Local
8FCC1E4A 3E598D81 96476875 E2F86C33
75B51661 B6556C5E 8F546E97 5197734B
C8C29AC7 E427C8E4 B9AAF5AA 80A75B3C
235

Advertisement

Table of Contents
loading

Table of Contents