Configuration Procedure For Automatic Requests - HP 830 Series Configuration Manual

Poe+ unified wired-wlan switch switching engine web-based
Hide thumbs Also See for HP 830 Series:
Table of Contents

Advertisement

Step
5.
Requesting a local
certificate
6.
Destroying the RSA key pair
7.
Retrieving and displaying a
certificate
8.
Retrieving and displaying a
CRL

Configuration procedure for automatic requests

Task
1.
Creating a PKI entity
2.
Creating a PKI domain
Remarks
Required.
When requesting a certificate, an entity introduces itself to the CA by
providing its identity information and public key. The identity information
and public key are the major components of the certificate.
A certificate request can be submitted to a CA in online mode or offline
mode.
In online mode, if the request is granted, the local certificate will be sent
to the local system automatically.
In offline mode, you must retrieve the local certificate by using an
out-of-band means such as phone, disk, or email.
IMPORTANT:
If a local certificate already exists, you cannot perform the local certificate
retrieval operation. To avoid a possible mismatch between the local certificate
and registration information, you must remove the CA certificate and local
certificate first.
Optional.
Delete the existing RSA key pair and the corresponding local certificate.
If the certificate to be retrieved contains an RSA key pair, you must delete the
existing key pair. Otherwise, the retrieving operation will fail.
Optional.
Retrieve an existing certificate.
Optional.
Retrieve a CRL and display its contents.
Remarks
Required.
Create a PKI entity and configure the identity information.
A certificate is the binding of a public key and the identity information of an
entity, where the DN shows the identity information of the entity. A CA
identifies a certificate applicant by a unique entity DN.
The DN settings of an entity need to be compliant with the CA certificate
issue policy, or the certificate request might be rejected. You must know the
policy to determine mandatory or optional entity parameters.
Required.
Create a PKI domain and set the certificate request mode to Auto.
Before requesting a PKI certificate, an entity needs to be configured with
enrollment information, which is called a PKI domain.
A PKI domain is significant only to PKI and is intended as a reference for
other applications such as IKE and SSL.
426

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents