285 
Make sure the version of the OpenCA server is later than version 0.9.2 because the earlier versions 
do not support SCEP. 
Configuring the device 
1.  Synchronize the device's system time with the CA server for the device to correctly request 
certificates. (Details not shown.) 
2.  Create a PKI entity named aaa and configure the common name, country code, organization 
name, and OU for the entity. 
<Device> system-view 
[Device] pki entity aaa 
[Device-pki-entity-aaa] common-name rnd 
[Device-pki-entity-aaa] country CN 
[Device-pki-entity-aaa] organization test 
[Device-pki-entity-aaa] organization-unit software 
[Device-pki-entity-aaa] quit 
3.  Configure a PKI domain: 
# Create a PKI domain named openca and enter its view. 
[Device] pki domain openca 
# Set the name of the trusted CA to myca. 
[Device-pki-domain-openca] ca identifier myca 
# Configure the certificate request URL. The URL is in the format http://host/cgi-bin/pki/scep, 
where host is the host IP address of the OpenCA server. 
[Device-pki-domain-openca] certificate request url 
http://192.168.222.218/cgi-bin/pki/scep 
# Configure the device to send certificate requests to the RA. 
[Device-pki-domain-openca] certificate request from ra 
# Specify PKI entity aaa for certificate request. 
[Device-pki-domain-openca] certificate request entity aaa 
# Configure a general-purpose RSA key pair named abc with a length of 1024 bits. 
[Device-pki-domain-openca] public-key rsa general name abc length 1024 
[Device-pki-domain-openca] quit 
4.  Generate the RSA key pair. 
[Device] public-key local create rsa name abc 
The range of public key modulus is (512 ~ 2048). 
If the key modulus is greater than 512,it will take a few minutes. 
Press CTRL+C to abort. 
Input the modulus length [default = 1024]: 
Generating Keys... 
..........................++++++ 
.....................................++++++ 
Create the key pair successfully. 
5.  Request a local certificate: 
# Obtain the CA certificate and save it locally. 
[Device] pki retrieve-certificate domain openca ca 
The trusted CA's finger print is: 
    MD5  fingerprint:5AA3 DEFD 7B23 2A25 16A3 14F4 C81C C0FA 
    SHA1 fingerprint:9668 4E63 D742 4B09 90E0 4C78 E213 F15F DC8E 9122 
Is the finger print correct?(Y/N):y 
Retrieved the certificates successfully.