Configuring Pki Certificate Verification; Configuring Crl-Checking-Enabled Pki Certificate Verification - HP A5830 Series Configuration Manual

Security switch
Hide thumbs Also See for A5830 Series:
Table of Contents

Advertisement

To do...
2.
Retrieve a
certificate
manually.
If a PKI domain already has a CA certificate, you cannot retrieve another CA certificate for it. This
restriction helps avoid inconsistency between the certificate and registration information resulting from
configuration changes. To retrieve a new CA certificate, first use the pki delete-certificate command to
delete the existing CA certificate and the local certificate.
The pki retrieval-certificate configuration is not saved in the configuration file.
Be sure that the switch's system time falls in the validity period of the certificate so that the certificate is
valid.

Configuring PKI certificate verification

A certificate needs to be verified before being used. Verifying a certificate involves checking whether the
certificate is signed by the CA and whether the certificate has expired or has been revoked.
You can specify whether to perform CRL checking during certificate verification. If you enable CRL
checking, CRLs are used in verification of a certificate, and you must retrieve the CA certificate and CRLs
to the local switch before the certificate verification. If you disable CRL checking, you only need to
retrieve the CA certificate.

Configuring CRL-checking-enabled PKI certificate verification

To do...
1.
Enter system view.
2.
Enter PKI domain view.
3.
Specify the URL of the CRL
distribution point.
4.
Set the CRL update period.
5.
Enable CRL checking.
6.
Return to system view.
7.
Retrieve the CA certificate.
8.
Retrieve CRLs.
Use the command...
pki retrieval-certificate { ca | local } domain
Online
domain-name
pki import-certificate { ca | local } domain
Offline
domain-name { der | p12 | pem } [ filename
filename ]
Use the command...
system-view
pki domain domain-name
crl url url-string
crl update-period hours
crl check enable
quit
See
"Retrieving a certificate
manually."
pki retrieval-crl domain domain-
name
Optional.
No CRL distribution point URL is
specified by default.
Optional.
By default, the CRL update period
depends on the next update field
in the CRL file.
Optional.
Enabled by default.
Required.
Required.
155
Remarks
Required.
Use either command.
Remarks

Advertisement

Table of Contents
loading

Table of Contents