Submitting A Pki Certificate Request; Submitting A Certificate Request In Auto Mode; Submitting A Certificate Request In Manual Mode - 3Com 4500G Family Configuration Manual

24/48 port
Hide thumbs Also See for 4500G Family:
Table of Contents

Advertisement

Currently, up to two PKI domains can be created on a device.
The CA name is required only when you retrieve a CA certificate. It is not used when in local
certificate request.
Currently, the URL of the server for certificate request does not support domain name resolving.

Submitting a PKI Certificate Request

When requesting a certificate, an entity introduces itself to the CA by providing its identity information
and public key, which will be the major components of the certificate. A certificate request can be
submitted to a CA in two ways: online and offline. In offline mode, a certificate request is submitted to a
CA by an "out-of-band" means such as phone, disk, or e-mail.
Online certificate request falls into two categories: manual mode and auto mode.

Submitting a Certificate Request in Auto Mode

In auto mode, an entity automatically requests a certificate through the SCEP from the CA server if it
has no local certificate for an application to work with PKI.
Follow these steps to configure an entity to submit a certificate request in auto mode:
To do...
Enter system view
Enter PKI domain view
Set the certificate request mode to
auto
After the certificate is to expire or has expired, the entity does not initiate a re-request automatically. To
have a new local certificate, you need to request one manually.

Submitting a Certificate Request in Manual Mode

In manual mode, you need to retrieve a CA certificate, generate a local RSA key pair, and submit a local
certificate request for an entity.
The goal of retrieving a CA certificate is to verify the authenticity and validity of a local certificate.
Generating an RSA key pair is an important step in certificate request. The key pair includes a public
key and a private key. The private key is kept by the user, while the public key is transferred to the CA
along with some other information. For detailed information about RSA key pair configuration, refer to
Public Key Configuration in the Security Volume.
Follow these steps to submit a certificate request in manual mode:
Use the command...
system-view
pki domain domain-name
certificate request mode auto
[ key-length key-length | password
{ cipher | simple } password ] *
1-7
Remarks
Required
Manual by default

Hide quick links:

Advertisement

Chapters

Table of Contents
loading

Table of Contents