282 
d.  Specify the path for certificate service in the Local path box. 
e.  Specify a unique TCP port number for the default website to avoid conflict with existing 
services. In this example, port 8080 is used. 
Configuring the device 
1.  Synchronize the device's system time with the CA server for the device to correctly request 
certificates. (Details not shown.) 
2.  Create an entity named aaa and set the common name to test. 
<Device> system-view 
[Device] pki entity aaa 
[Device-pki-entity-aaa] common-name test 
[Device-pki-entity-aaa] quit 
3.  Configure a PKI domain: 
# Create a PKI domain named winserver and enter its view. 
[Device] pki domain winserver 
# Set the name of the trusted CA to myca. 
[Device-pki-domain-winserver] ca identifier myca 
# Configure the certificate request URL. The URL format is 
http://host:port/certsrv/mscep/mscep.dll, where host:port is the host IP address and port 
number of the CA server. 
[Device-pki-domain-winserver] certificate request url 
http://4.4.4.1:8080/certsrv/mscep/mscep.dll 
# Configure the device to send certificate requests to ra. 
[Device-pki-domain-winserver] certificate request from ra 
# Set the PKI entity name to aaa. 
[Device-pki-domain-winserver] certificate request entity aaa 
# Configure a general-purpose RSA key pair named abc with a length of 1024 bits. 
[Device-pki-domain-winserver] public-key rsa general name abc length 1024 
[Device-pki-domain-winserver] quit 
4.  Generate the RSA local key pair. 
[Device] public-key local create rsa name abc 
The range of public key modulus is (512 ~ 2048). 
If the key modulus is greater than 512,it will take a few minutes. 
Press CTRL+C to abort. 
Input the modulus length [default = 1024]: 
Generating Keys... 
..........................++++++ 
.....................................++++++ 
Create the key pair successfully. 
5.  Request a local certificate: 
# Obtain the CA certificate and save it locally. 
[Device] pki retrieve-certificate domain winserver ca 
The trusted CA's finger print is: 
    MD5  fingerprint:766C D2C8 9E46 845B 4DCE 439C 1C1F 83AB 
    SHA1 fingerprint:97E5 DDED AB39 3141 75FB DB5C E7F8 D7D7 7C9B 97B4 
Is the finger print correct?(Y/N):y 
Retrieved the certificates successfully. 
# Submit a certificate request manually.