3Com Baseline 2928 PWR Plus User Manual page 428

Baseline switch 2900 family
Hide thumbs Also See for Baseline 2928 PWR Plus:
Table of Contents

Advertisement

Item
Type the URL of the RA.
The entity will submit the certificate request to the server at this URL through the
SCEP protocol. The SCEP protocol is intended for communication between an
entity and an authentication authority.
Requesting URL
In offline mode, this item is optional; while in other modes, this item is required.
Currently, this item does not support domain name resolution.
LDAP IP
Type the IP address, port number and version of the LDAP server.
Port
In a PKI system, the storage of certificates and CRLs is a crucial problem, which
is usually addressed by deploying an LDAP server.
Version
Request Mode
Select the online certificate request mode, which can be auto or manual.
Select this check box to display the password in cipher text.
Password
This check box is available only when the certificate request mode is set to
Encrypt
Auto.
Type the password for certificate revocation.
Password
This item is available only when the certificate request mode is set to Auto.
Specify the hash algorithm and fingerprint for verification of the CA root
certificate.
Hash
Upon receiving the root certificate of the CA, an entity needs to verify the
fingerprint of the root certificate, namely, the hash value of the root certificate
content. This hash value is unique to every certificate. If the fingerprint of the
root certificate does not match the one configured for the PKI domain, the entity
will reject the root certificate.
Fingerprint
The fingerprint of the CA root certificate is required when the certificate request
mode is Auto, and can be omitted when the certificate request mode is Manual.
When it is omitted, no CA root certificate verification occurs automatically and
you need to verify the CA server by yourself.
Set the polling interval and attempt limit for querying the certificate request
Polling Count
status.
After an entity makes a certificate request, the CA may need a long period of
time if it verifies the certificate request in manual mode. During this period, the
Polling Interval
applicant needs to query the status of the request periodically to get the
certificate as soon as possible after the certificate is signed.
Enable CRL
Select this box to specify that CRL checking is required during certificate
Checking
verification.
Type the CRL update period, that is, the interval at which the PKI entity
downloads the latest CRLs.
CRL Update
This item is available when the Enable CRL Checking check box is selected.
Period
By default, the CRL update period depends on the next update field in the CRL
file.
Description
1-9

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents