Submitting A Pki Certificate Request - HP 12500 Series Configuration Manual

Routing
Table of Contents

Advertisement

content. This hash value is unique to every certificate. If the fingerprint of the root certificate does not
match the one configured for the PKI domain, the entity will reject the root certificate.
To configure a PKI domain:
Step
1.
Enter system view.
2.
Create a PKI domain and
enter its view.
3.
Specify the trusted CA.
4.
Specify the entity for
certificate request.
5.
Specify the authority for
certificate request.
6.
Configure the URL of the
server for certificate request.
7.
Configure the polling interval
and attempt limit for querying
the certificate request status.
8.
Specify the LDAP server.
9.
Configure the fingerprint for
root certificate verification.

Submitting a PKI certificate request

When requesting a certificate, an entity introduces itself to the CA by providing its identity information
and public key, which will be the major components of the certificate. A certificate request can be
submitted to a CA in offline mode or online mode. In offline mode, a certificate request is submitted to
a CA by an "out-of-band" means such as phone, disk, or email.
Command
system-view
pki domain domain-name
ca identifier name
certificate request entity
entity-name
certificate request from { ca | ra }
certificate request url url-string
certificate request polling { count
count | interval minutes }
ldap-server ip ip-address [ port
port-number ] [ version
version-number ]
root-certificate fingerprint { md5 |
sha1 } string
296
Remarks
N/A
No PKI domain exists by default.
You can create up to 32 PKI
domains on a switch.
No trusted CA is specified by
default.
The CA name is required only
when you retrieve a CA certificate.
It is not used for requesting the
local certificate.
No entity is specified by default.
The specified entity must exist.
No authority is specified by
default.
No URL is configured by default.
The URL of the server for certificate
request does not support domain
name resolution.
Optional.
The polling is executed for up to 50
times at the interval of 20 minutes
by default.
Optional.
No LDP server is specified by
default.
Required when the certificate
request mode is auto and optional
when the certificate request mode
is manual. In the latter case, if you
do not configure this command, the
fingerprint of the root certificate
must be verified manually.
No fingerprint is configured by
default.

Advertisement

Table of Contents
loading

Table of Contents