432
Figure 442 Key pair parameter configuration page
Destroying the RSA key pair
1. From the navigation tree, select Authentication > PKI.
2. Click the Certificate tab.
3. Click Destroy Key.
4. Click Apply to destroy the existing RSA key pair and the corresponding local certificate.
Figure 443 Key pair destruction page
Retrieving and displaying a certificate
You can retrieve an existing CA certificate or local certificate from the CA server and save it locally in
offline or online mode. In offline mode, you must retrieve a certificate by an out-of-band means such as
FTP, disk, or email, and then import it into the local PKI system. By default, the retrieved certificate is saved
in a file under the root directory of the device, and the filename is domain-name_ca.cer for the CA
certificate, or domain-name_local.cer for the local certificate.
To retrieve a certificate:
1. From the navigation tree, select Authentication > PKI.
2. Click the Certificate tab.
3. Click Retrieve Cert.