EasyManuals Logo

HPE FlexFabric 5940 SERIES User Manual

HPE FlexFabric 5940 SERIES
571 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #285 background imageLoading...
Page #285 background image
272
Manually requesting a certificate
Before you manually submit a certificate request, make sure the CA certificate exists and a key pair
is specified for the PKI domain.
• The CA certificate is used to verify the authenticity and validity of the obtained local certificate.
• The key pair is used for certificate request. Upon receiving the public key and the identity
information, the CA signs and issues a certificate.
After the CA issues the certificate, the device obtains and saves it locally.
To manually request a certificate:
Step Command Remarks
1. Enter system view.
system-view
N/A
2. Enter PKI domain view.
pki domain
domain-name N/A
3. Set the certificate
request mode to
manual.
certificate request mode manual
By default, the manual request
mode applies.
4. Return to system view.
quit
N/A
5. Obtain a CA certificate.
See "Obtaining certificates." N/A
6. Submit a certificate
request or generate a
certificate request in
PKCS#10 format.
pki request-certificate domain
domain-name [
password
password ]
[
pkcs10
[
filename
filename ] ]
This command is not saved in
the configuration file.
This command triggers the PKI
entity to automatically generate
a key pair if the key pair
specified in the PKI domain
does not exist. The name,
algorithm, and length of the key
pair are configured in the PKI
domain.
Aborting a certificate request
Before the CA issues a certificate, you can abort a certificate request and change its parameters,
such as the common name, country code, or FQDN. You can use the display pki certificate
request-status command to display the status of a certificate request.
Alternatively, you also can remove a PKI domain to abort the associated certificate request.
To abort a certificate request:
Step Command Remarks
1. Enter system view.
system-view
N/A
2. Abort a certificate request.
pki abort-certificate-request
domain
domain-name
This command is not saved in the
configuration file.
Obtaining certificates
You can obtain the CA certificate, local certificates, and peer certificates related to a PKI domain from
a CA and save them locally for higher lookup efficiency. To do so, use either the offline mode or the
online mode:

Table of Contents

Other manuals for HPE FlexFabric 5940 SERIES

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HPE FlexFabric 5940 SERIES and is the answer not in the manual?

HPE FlexFabric 5940 SERIES Specifications

General IconGeneral
BrandHPE
ModelFlexFabric 5940 SERIES
CategorySwitch
LanguageEnglish

Related product manuals