1840
C
97: PKI C
HAPTER
Displaying and
Maintaining PKI
PKI Configuration
Examples
Configuring a PKI Entity
to Request a Certificate
from a CA
ONFIGURATION
To do...
Display the contents of a
certificate or the status of
certificate request
Display CRs
Display the information of
one or all certificate attribute
groups
Display the information of
one or all certificate
attribute-based access control
policies
c
CAUTION:
The SCEP plug-in is required when you use the Windows Server as the CA. In
■
this case, when configuring the PKI domain, you need to use the certificate
request from ra command to specify that the entity requests a certificate
from an RA.
The SCEP plug-in is not required when RSA Keon is used. In this case, when
■
configuring a PKI domain, you need to use the certificate request from ca
command to specify that the entity requests a certificate from a CA.
n
RSA Keon is used on the CA server in this configuration example.
Network requirements
The device submits a local certificate request to the CA server;
■
The device acquires CRLs for certificate validation.
■
Network diagram
Figure 533 Diagram for configuring a PKI entity to request a certificate from a CA
Use the command...
display pki certificate { { ca | local }
domain domain-name | request-status }
display pki crl domain domain-name
display pki certificate attribute-group
{ group-name | all }
display pki certificate
access-control-policy { policy-name | all }
Remarks
Available in any
view
Available in any
view
Available in any
view
Available in any
view
Need help?
Do you have a question about the MSR 50 Series and is the answer not in the manual?
Questions and answers