Retrieving A Certificate Manually; Configuration Guidelines; Configuration Procedure - HP 12500 Series Configuration Manual

Routing
Table of Contents

Advertisement

Make sure that the entity and the CA are synchronous in system time. Otherwise, the validity period
of the certificate is abnormal.
The pki request-certificate domain configuration is not saved in the configuration file.

Configuration procedure

To submit a certificate request in manual mode:
Step
1.
Enter system view.
2.
Enter PKI domain view.
3.
Set the certificate request
mode to manual.
4.
Return to system view.
5.
Retrieve a CA certificate
manually.
6.
Generate a local RSA or
ECDSA key pair.
7.
Submit a local certificate
request manually.

Retrieving a certificate manually

You can download CA certificates and local certificates from the CA server and save them locally. To do
so, use either the offline mode or the online mode. In offline mode, you must retrieve a certificate by an
out-of-band means like FTP, disk, or email, and then import it into the local PKI system.
Certificate retrieval serves the following purposes:
Locally store the certificates associated with the local security domain for improved query efficiency
and reduced query count
Prepare for certificate verification

Configuration guidelines

Before retrieving a local certificate in online mode, complete LDAP server configuration.
If a PKI domain already has a CA certificate, do not retrieve another CA certificate for it. Otherwise,
inconsistency might exist between the certificate and registration information if the configuration
changes. To retrieve a new CA certificate, first use the pki delete-certificate command to delete the
existing local CA certificate and the local certificate.
The pki retrieval-certificate configuration is not saved in the configuration file.
Make sure that the system time of the switch falls in the validity period of the certificate so that the
certificate is valid.
Configuration procedure
To retrieve a certificate manually:
Command
system-view
pki domain domain-name
certificate request mode manual
quit
See
"Retrieving a certificate
manually"
public-key local create { ecdsa |
rsa }
pki request-certificate domain
domain-name [ password ]
[ pkcs10 [ filename filename ] ]
298
Remarks
N/A
N/A
Optional.
Manual by default.
N/A
N/A
No local RSA or ECDSA key pair
exists by default.
N/A

Advertisement

Table of Contents
loading

Table of Contents