EasyManuals Logo
Home>HP>Switch>5120 EI Switch Series

HP 5120 EI Switch Series User Manual

HP 5120 EI Switch Series
304 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #205 background imageLoading...
Page #205 background image
195
CAUTION:
ï‚· If a PKI domain already has a CA certificate, you cannot retrieve another CA certificate for it. This restriction
helps avoid inconsistency between the certificate and registration information resulted from configuration
changes. To retrieve a new CA certificate, use the pki delete-certificate command to delete the existing CA
certificate and the local certificate first.
ï‚· The pki retrieval-certificate configuration will not be saved in the configuration file.
ï‚· Be sure that the device system time falls in the validity period of the certificate so that the certificate is valid.
Configuring PKI certificate verification
A certificate needs to be verified before being used. Verifying a certificate is to check whether the
certificate is signed by the CA and whether the certificate has expired or been revoked.
Before verifying a certificate, you must retrieve the CA certificate.
You can specify whether CRL checking is required in certificate verification. If you enable CRL checking,
CRLs will be used in verification of a certificate.
Configuring CRL-checking-enabled PKI certificate verification
Follow these steps to configure CRL-checking-enabled PKI certificate verification:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter PKI domain view
pki domain domain-name
—
Specify the URL of the CRL
distribution point
crl url url-string
Optional
No CRL distribution point URL is
specified by default.
Set the CRL update period
crl update-period hours
Optional
By default, the CRL update period
depends on the next update field
in the CRL file.
Enable CRL checking
crl check enable
Optional
Enabled by default
Return to system view
quit
—
Retrieve the CA certificate
See ―Retrieving a certificate
manually―
Required
Retrieve CRLs
pki retrieval-crl domain domain-
name
Required
Verify the validity of a certificate
pki validate-certificate { ca | local
} domain domain-name
Required
Configuring CRL-checking-disabled PKI certificate verification
Follow these steps to configure CRL-checking-disabled PKI certificate verification:
To do…
Use the command…
Remarks
Enter system view
system-view
—

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HP 5120 EI Switch Series and is the answer not in the manual?

HP 5120 EI Switch Series Specifications

General IconGeneral
BrandHP
Model5120 EI Switch Series
CategorySwitch
LanguageEnglish

Related product manuals