393
as shown in a. Then, click Apply to destroy the existing RSA key pair and the corresponding local
certificate.
a. Key pair destruction page
Return to Configuration task list for requesting a certificate manually.
Return to Configuration task list for requesting a certificate automatically.
Retrieving a certificate
You can download an existing CA certificate or local certificate from the CA server and save it locally. To
do so, you can use two ways: online and offline. In offline mode, you need to retrieve a certificate by an
out-of-band means like FTP, disk, e-mail and then import it into the local PKI system.
Select Authentication PKI from the navigation tree, and then select the Certificate tab to enter the page
displaying existing PKI certificates, as shown in a. Click Retrieve Cert to enter PKI certificate retrieval page,
as shown in a.
a. PKI certificate retrieval page
2. Configuration items for retrieving a PKI certificate
Item Descri
tion
Domain Name
Select the PKI domain for the certificate.
Certificate Type
Select the type of the certificate to be retrieved, which can be CA or local.
Enable Offline
Mode
Select this check box to retrieve a certificate in offline mode (that is, by an out-of-band
means like FTP, disk, or e-mail) and then import the certificate into the local PKI system.
The following configuration items are displayed if this check box is selected.
Get File From
Device
Specify the path and name of the certificate file.