Certificate Request From A Windows 2003 Ca Server - HP 3600 v2 Series Configuration Manual

Hide thumbs Also See for 3600 v2 Series:
Table of Contents

Advertisement

You can also use display pki certificate ca domain and display pki crl domain to display detailed
information about the CA certificate and CRLs. For more information about the commands, see Security
Command Reference.

Certificate request from a Windows 2003 CA server

Network requirements
Configure PKI entity Device to request a local certificate from the CA server.
Figure 81 Network diagram
Configuring the CA server
1.
Install the certificate service suites:
a.
Select Control Panel > Add or Remove Programs from the start menu.
b.
Select Add/Remove Windows Components > Certificate Services.
Click Next to begin the installation.
c.
2.
Install the SCEP add-on:
Because a CA server running the Windows 2003 server does not support SCEP by default, you
must install the SCEP add-on so that the switch can register and obtain its certificate automatically.
After the SCEP add-on installation completes, a URL is displayed, which you must configure on the
switch as the URL of the server for certificate registration.
3.
Modify the certificate service attributes:
a.
Select Control Panel > Administrative Tools > Certificate Authority from the start menu.
If the CA server and SCEP add-on have been installed successfully, there should be two
certificates issued by the CA to the RA.
b.
Right-click the CA server in the navigation tree and select Properties > Policy Module.
c.
Click Properties and select Follow the settings in the certificate template, if applicable.
Otherwise, automatically issue the certificate.
4.
Modify the Internet Information Services (IIS) attributes:
a.
Select Control Panel > Administrative Tools > Internet Information Services (IIS) Manager from
the start menu.
b.
Select Web Sites from the navigation tree.
c.
Right-click Default Web Site and select Properties > Home Directory.
d.
Specify the path for certificate service in the Local path text box.
To avoid conflict with existing services, specify an available port number as the TCP port
number of the default website.
After completing the configuration, make sure the system clock of the switch is synchronous to that of the
CA server, so that that the switch can request a certificate normally.
263

Advertisement

Table of Contents
loading

Table of Contents