Configuring Pki Certificate Verification; Configuring Crl-Checking-Enabled Pki Certificate Verification - HP 3600 v2 Series Security Configuration Manual

Hide thumbs Also See for 3600 v2 Series:
Table of Contents

Advertisement

To do...
Enter system view
Retrieve a
certificate
manually
CAUTION:
If a PKI domain already has a CA certificate, you cannot retrieve another CA certificate for it. This
restriction helps avoid inconsistency between the certificate and registration information resulted from
configuration changes. To retrieve a new CA certificate, use the pki delete-certificate command to
delete the existing CA certificate and the local certificate first.
The pki retrieval-certificate configuration will not be saved in the configuration file.
Be sure that the switch's system time falls in the validity period of the certificate so that the certificate is
valid.

Configuring PKI certificate verification

A certificate needs to be verified before being used. Verifying a certificate is to check whether the
certificate is signed by the CA and whether the certificate has expired or been revoked.
You can specify whether to perform CRL checking during certificate verification. If you enable CRL
checking, CRLs will be used in verification of a certificate, and you must retrieve the CA certificate and
CRLs to the local switch before the certificate verification. If you disable CRL checking, you only need to
retrieve the CA certificate.

Configuring CRL-checking-enabled PKI certificate verification

Follow these steps to configure CRL-checking-enabled PKI certificate verification:
To do...
Enter system view
Enter PKI domain view
Specify the URL of the CRL
distribution point
Set the CRL update period
Enable CRL checking
Return to system view
Use the command...
system-view
pki retrieval-certificate { ca | local } domain
Online
domain-name
pki import-certificate { ca | local } domain
Offline
domain-name { der | p12 | pem } [ filename
filename ]
Use the command...
system-view
pki domain domain-name
crl url url-string
crl update-period hours
crl check enable
quit
248
Remarks
Required
Use either command.
Remarks
Optional
No CRL distribution point URL is
specified by default.
Optional
By default, the CRL update period
depends on the next update field in
the CRL file.
Optional
Enabled by default

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

A3100-48 v2

Table of Contents