255
Configuration procedure
1. Configure the CA server
• Install the certificate service suites
From the start menu, select Control Panel > Add or Remove Programs, and then select Add/Remove
Windows Components > Certificate Services and click Next to begin the installation.
• Install the SCEP add-on
Because a CA server running the Windows 2003 server does not support SCEP by default, you must
install the SCEP add-on so that the switch can register and obtain its certificate automatically. After the
SCEP add-on installation completes, a URL is displayed, which you must configure on the switch as the
URL of the server for certificate registration.
• Modify the certificate service attributes
From the start menu, select Control Panel > Administrative Tools > Certificate Authority. If the CA server
and SCEP add-on have been installed successfully, there should be two certificates issued by the CA to
the RA. Right-click on the CA server in the navigation tree and select Properties > Policy Module. Click
Properties and then select Follow the settings in the certificate template, if applicable. Otherwise,
automatically issue the certificate.
• Modify the Internet Information Services (IIS) attributes
From the start menu, select Control Panel > Administrative Tools > Internet Information Services (IIS)
Manager and then select Web Sites from the navigation tree. Right-click on Default Web Site and select
Properties > Home Directory. Specify the path for certificate service in the Local path text box. To avoid
conflict with existing services, specify an available port number as the TCP port number of the default
website.
After completing the configuration, check that the system clock of the switch is synchronous to that of the
CA server, ensuring that the switch can request a certificate normally.
2. Configure the switch
• Configure the entity DN
# Configure the entity name as aaa and the common name as device.
<Device> system-view
[Device] pki entity aaa
[Device-pki-entity-aaa] common-name device
[Device-pki-entity-aaa] quit
• Configure the PKI domain
# Create PKI domain torsa and enter its view.
[Device] pki domain torsa
# Configure the name of the trusted CA as myca.
[Device-pki-domain-torsa] ca identifier myca
# Configure the URL of the registration server in the format of http://host:port/ certsrv/mscep/mscep.dll,
where host:port indicates the IP address and port number of the CA server.
[Device-pki-domain-torsa] certificate request url
http://4.4.4.1:8080/certsrv/mscep/mscep.dll
# Set the registration authority to RA.
[Device-pki-domain-torsa] certificate request from ra
# Specify the entity for certificate request as aaa.