Submitting A Pki Certificate Request - 3Com Switch 4800G 24-Port Configuration Manual

Switch 4800g family 24-port, pwr 24-port, 48-port, pwr 48-port, 24-port sfp
Hide thumbs Also See for Switch 4800G 24-Port:
Table of Contents

Advertisement

Submitting a PKI
Certificate Request
Submitting a Certificate
Request in Auto Mode
Submitting a Certificate
Request in Manual
Mode
To do...
Configure the URL of
the server for certificate
request
Configure the polling
interval and maximum
number of attempts for
querying the certificate
request status
Specify the LDAP server
Configure the
fingerprint for root
certificate validation
n
Currently, up to two PKI domains can be created on a device.
The CA name is required only when you retrieve a CA certificate. It is not used
when in local certificate request.
When requesting a certificate, an entity introduces itself to the CA by providing its
identity information and public key, which will be the major components of the
certificate that the CA may issue to the entity. A certificate request can be
submitted to a CA in two ways: online and offline. In offline mode, a certificate
request is submitted to a CA by an "out-of-band" means such as phone, disk, or
e-mail.
Online certificate request falls into two categories: manual mode and auto mode.
In auto mode, an entity automatically requests a certificate through the SCEP
protocol when it has no local certificate or the present certificate is about to
expire.
Follow these steps to configure an entity to submit a certificate request in auto
mode:
To do...
Enter system view
Enter PKI domain view
Set the certificate request
mode to auto
In manual mode, you need to retrieve a CA certificate, generate a local RSA key
pair, and submit a local certificate request for an entity.
The goal of retrieving a CA certificate is to verify the authenticity and validity of a
local certificate.

Submitting a PKI Certificate Request

Use the command...
certificate request url
url-string
certificate request polling
{ count count | interval
minutes }
ldap-server ip ip-address
[ port port-number ]
[ version version-number ]
root-certificate fingerprint
{ md5 | sha1 } string
Use the command...
system-view
pki domain domain-name
certificate request mode auto
[ key-length key-length | password
{ cipher | simple } password ] *
Remarks
Required
No URL is configured by default.
Optional
The polling is executed for up to 50
times at the interval of 20 minutes
by default.
Optional
No LDP server is specified by
default.
Optional
No fingerprint is configured by
default.
Remarks
-
-
Required
Manual by default
1225

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents