1-17
Figure 1-18 PKI domain list
Figure 1-19 Configure a PKI domain
z Type torsa as the PKI domain name.
z Type myca as the CA identifier.
z Select aaa as the local entity.
z Select CA as the authority for certificate request.
z Type http://4.4.4.133:446/c95e970f632d27be5e8cbf80e971d9c4a9a93337 as the URL for
certificate request. The URL must be in the format of http://host:port/Issuing Jurisdiction ID, where
Issuing Jurisdiction ID is the hexadecimal string generated on the CA.
z Select Manual as the certificate request mode.
z Click Display Advanced Config to display the advanced configuration items.
z Select the Enable CRL Checking check box.
z Type http://4.4.4.133:447/myca.crl as the CRL URL.
z Click Apply. A dialog box appears, asking "Fingerprint of the root certificate not specified. No root
certificate validation will occur. Continue?" Click OK.
# Generate an RSA key pair.