Pki Configuration Examples; Certificate Request From An Rsa Keon Ca Server - HP 12500 Series Configuration Manual

Routing
Table of Contents

Advertisement

PKI configuration examples

The SCEP add-on is required when you use the Windows Server as the CA. In this case, when you
configure the PKI domain, you must the certificate request from ra command to specify that the entity
requests a certificate from an RA.
The SCEP add-on is not required when RSA Keon is used. In this case, when you configure a PKI domain,
you must use the certificate request from ca command to specify that the entity requests a certificate from
a CA.

Certificate request from an RSA Keon CA server

Network requirements
The switch submits a local certificate request to the CA server and the switch acquires the CRLs for
certificate verification.
Figure 103 Network diagram
Configuring the CA server
Create a CA server named myca:
1.
Configure these basic attributes on the CA server first:
a.
Nickname—Name of the trusted CA.
Subject DN—DN information of the CA, including the Common Name (CN), Organization
Unit (OU), Organization (O), and Country (C).
Use the default settings for the other attributes.
b.
Configure extended attributes.
2.
After configuring the basic attributes, you need to perform configuration on the jurisdiction
configuration page of the CA server. Select the proper extension profiles, enable the SCEP
autovetting function, and add the IP address list for SCEP autovetting.
Configure the CRL distribution behavior.
3.
After completing the configuration, you need to perform CRL related configurations. In this
example, select the local CRL distribution mode of HTTP and set the HTTP URL to
http://4.4.4.133:447/myca.crl.
After the configuration, make sure that the system clock of the switch is synchronous to that of the CA, so
that the switch can request certificates and retrieve CRLs properly.
Configuring the switch
# Configure the entity name as aaa and the common name as switch.
<Switch> system-view
[Switch] pki entity aaa
[Switch-pki-entity-aaa] common-name switch
302

Advertisement

Table of Contents
loading

Table of Contents