Configuring Pki Certificate Verification - 3Com 4500G Family Configuration Manual

24/48 port
Hide thumbs Also See for 4500G Family:
Table of Contents

Advertisement

Prepare for certificate verification.
Before retrieving a local certificate in online mode, be sure to complete LDAP server configuration.
Follow these steps to retrieve a certificate manually:
To do...
Enter system view
Retrieve a
certificate
manually
If a PKI domain already has a CA certificate, you cannot retrieve another CA certificate for it. This is
in order to avoid inconsistency between the certificate and registration information due to related
configuration changes. To retrieve a new CA certificate, use the pki delete-certificate command
to delete the existing CA certificate and local certificate first.
The pki retrieval-certificate configuration will not be saved in the configuration file.
Be sure that the device system time falls in the validity period of the certificate so that the certificate
is valid.

Configuring PKI Certificate Verification

A certificate needs to be verified before being used. Verifying a certificate is to check that the certificate
is signed by the CA and that the certificate has neither expired nor been revoked.
Before verifying a certificate, you need to retrieve the CA certificate.
You can specify whether CRL checking is required in certificate verification. If you enable CRL checking,
CRLs will be used in verification of a certificate.
Configuring CRL-checking-enabled PKI certificate verification
Follow these steps to configure CRL-checking-enabled PKI certificate verification:
To do...
Enter system view
Enter PKI domain view
Specify the URL of the CRL
distribution point
Set the CRL update period
Enable CRL checking
Return to system view
Retrieve the CA certificate
system-view
pki retrieval-certificate { ca | local } domain
Online
domain-name
pki import-certificate { ca | local } domain
Offline
domain-name { der | p12 | pem } [ filename
filename ]
Use the command...
system-view
pki domain domain-name
crl url url-string
crl update-period hours
crl check enable
quit
Refer to
Retrieving a Certificate
Use the command...
Optional
No CRL distribution point URL is
specified by default.
Optional
By default, the CRL update period
depends on the next update field in
the CRL file.
Optional
Enabled by default
Required
1-9
Remarks
Required
Use either command.
Remarks

Hide quick links:

Advertisement

Chapters

Table of Contents
loading

Table of Contents