Configuration Guidelines; Configuration Procedure - HP 3600 v2 Series Configuration Manual

Hide thumbs Also See for 3600 v2 Series:
Table of Contents

Advertisement

needs to query the status of the request periodically to get the certificate as soon as possible after
the certificate is signed. You can configure the polling interval and count to query the request status.
IP address of the LDAP server—An LDAP server is usually deployed to store certificates and CRLs.
If this is the case, you must configure the IP address of the LDAP server.
Fingerprint for root certificate verification—After receiving the root certificate of the CA, an entity
needs to verify the fingerprint of the root certificate, namely, the hash value of the root certificate
content. This hash value is unique to every certificate. If the fingerprint of the root certificate does not
match the one configured for the PKI domain, the entity will reject the root certificate.

Configuration guidelines

Up to two PKI domains can be created on a switch.
The CA name is required only when you retrieve a CA certificate. It is not used when in local
certificate request.
The certificate request URL does not support domain name resolution.

Configuration procedure

To configure a PKI domain:
Step
1.
Enter system view.
2.
Create a PKI domain and
enter its view.
3.
Specify the trusted CA.
4.
Specify the entity for
certificate request.
5.
Specify the authority for
certificate request.
6.
Configure the certificate
request URL.
7.
Configure the polling interval
and attempt limit for querying
the certificate request status.
8.
Specify the LDAP server.
Command
system-view
pki domain domain-name
ca identifier name
certificate request entity
entity-name
certificate request from { ca | ra }
certificate request url url-string
certificate request polling { count
count | interval minutes }
ldap-server ip ip-address [ port
port-number ] [ version
version-number ]
253
Remarks
N/A
No PKI domain exists by default.
No trusted CA is specified by
default.
No entity is specified by default.
The specified entity must exist.
No authority is specified by
default.
No certificate request URL is
configured by default.
Optional.
The polling is executed for up to 50
times at the interval of 20 minutes
by default.
Optional.
No LDP server is specified by
default.

Advertisement

Table of Contents
loading

Table of Contents