HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 173

Configuration procedure, Retrieving a certificate manually, Configuration guidelines

Page 173 highlights

request-certificate domain command with the pkcs10 keyword. To save the request information to a local file, use the pki request-certificate domain command with the pkcs10 filename filename option. • Make sure the clocks of the entity and the CA are synchronous. Otherwise, the validity period of the certificate will be abnormal. • The configuration made by the pki request-certificate domain command is not saved in the configuration file. Configuration procedure To submit a certificate request in manual mode: Step 1. Enter system view. 2. Enter PKI domain view. 3. Set the certificate request mode to manual. 4. Return to system view. 5. Retrieve a CA certificate manually. 6. Generate a local RSA key pair. 7. Submit a local certificate request manually. Command system-view pki domain domain-name certificate request mode manual quit See "Retrieving a certificate manually" public-key local create rsa pki request-certificate domain domain-name [ password ] [ pkcs10 [ filename filename ] ] Remarks N/A N/A Optional. Manual by default. N/A N/A No local RSA key pair exists by default. N/A Retrieving a certificate manually You can download CA certificates, local certificates, or peer entity certificates from the CA server and save them locally. To do so, use either the offline mode or the online mode. In offline mode, you must retrieve a certificate by an out-of-band means like FTP, disk, or email, and then import it into the local PKI system. Certificate retrieval serves the following purposes: • Locally store the certificates associated with the local security domain for improved query efficiency and reduced query count • Prepare for certificate verification Configuration guidelines • Before retrieving a local certificate in online mode, be sure to complete the LDAP server configuration. • If a PKI domain already has a CA certificate, you cannot retrieve another CA certificate for it. This restriction helps avoid inconsistency between the certificate and registration information resulted from configuration changes. To retrieve a new CA certificate, use the pki delete-certificate command to delete the existing CA certificate and the local certificate first. 163

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

163
request-certificate domain
command with the
pkcs10
keyword. To save the request information to
a local file, use the
pki request-certificate domain
command with the
pkcs10 filename
filename
option.
Make sure the clocks of the entity and the CA are synchronous. Otherwise, the validity period of the
certificate will be abnormal.
The configuration made by the
pki request-certificate domain
command is not saved in the
configuration file.
Configuration procedure
To submit a certificate request in manual mode:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter PKI domain view.
pki domain
domain-name
N/A
3.
Set the certificate request
mode to manual.
certificate request mode manual
Optional.
Manual by default.
4.
Return to system view.
quit
N/A
5.
Retrieve a CA certificate
manually.
See "
Retrieving a certificate
manually
"
N/A
6.
Generate a local RSA key
pair.
public-key local create
rsa
No local RSA key pair exists by
default.
7.
Submit a local certificate
request manually.
pki request-certificate domain
domain-name
[
password
]
[
pkcs10
[
filename
filename
] ]
N/A
Retrieving a certificate manually
You can download CA certificates, local certificates, or peer entity certificates from the CA server and
save them locally. To do so, use either the offline mode or the online mode. In offline mode, you must
retrieve a certificate by an out-of-band means like FTP, disk, or email, and then import it into the local PKI
system.
Certificate retrieval serves the following purposes:
Locally store the certificates associated with the local security domain for improved query efficiency
and reduced query count
Prepare for certificate verification
Configuration guidelines
Before retrieving a local certificate in online mode, be sure to complete the LDAP server
configuration.
If a PKI domain already has a CA certificate, you cannot retrieve another CA certificate for it. This
restriction helps avoid inconsistency between the certificate and registration information resulted
from configuration changes. To retrieve a new CA certificate, use the
pki delete-certificate
command to delete the existing CA certificate and the local certificate first.