beautypg.com

Configuration procedure – H3C Technologies H3C WX3000E Series Wireless Switches User Manual

Page 296

background image

282

Configuration procedure

1.

Configure the CA server

Install the certificate server suites

From the start menu, select Control Panel > Add or Remove Programs, and then select Add/Remove
Windows Components > Certificate Services and click Next to begin the installation.

Install the SCEP plug-in

Because a CA server running the Windows 2003 server does not support SCEP by default, you must

install the SCEP plug-in so that the AC can register and obtain its certificate automatically. After the SCEP

plug-in installation completes, a URL is displayed, which you must configure on the AC as the URL of the

server for certificate registration.

Modify the certificate service attributes

From the start menu, select Control Panel > Administrative Tools > Certificate Authority. If the CA server

and SCEP plug-in have been installed successfully, there should be two certificates issued by the CA to

the RA. Right-click on the CA server in the navigation tree and select Properties > Policy Module. Click

Properties and then select Follow the settings in the certificate template, if applicable. Otherwise,
automatically issue the certificate.

Modify the Internet Information Services (IIS) attributes

From the start menu, select Control Panel > Administrative Tools > Internet Information Services (IIS)

Manager and then select Web Sites from the navigation tree. Right-click on Default Web Site and select

Properties > Home Directory. Specify the path for certificate service in the Local path text box. In addition,

specify an available port number as the TCP port number of the default Web site to avoid conflict with
existing services.
After completing the above configuration, check that the system clock of the AC is synchronous to that of

the CA server, ensuring that the AC can request a certificate normally.

2.

Configure the AC

Configure the entity DN

# Configure the entity name as aaa and the common name as AC.

system-view

[AC] pki entity aaa

[AC-pki-entity-aaa] common-name AC

[AC-pki-entity-aaa] quit

Configure the PKI domain

# Create PKI domain torsa and enter its view.

[AC] pki domain torsa

# Configure the name of the trusted CA as myca.

[AC-pki-domain-torsa] ca identifier myca

# Configure the URL of the registration server in the format of http://host:port/ certsrv/mscep/mscep.dll,
where host:port indicates the IP address and port number of the CA server.

[AC-pki-domain-torsa] certificate request url

http://4.4.4.1:8080/certsrv/mscep/mscep.dll

# Set the registration authority to RA.

[AC-pki-domain-torsa] certificate request from ra

# Specify the entity for certificate request as aaa.