beautypg.com

H3C Technologies H3C SecPath F1000-E User Manual

Page 313

background image

301

Figure 202 Retrieving the CA certificate

5.

Request a local certificate:

a.

From the navigation tree, select VPN > Certificate Management > Certificate.

b.

Click Request Cert.

c.

Select 1 for the PKI domain, and click Apply.
The system displays "Certificate request has been submitted."

d.

Click OK to confirm.

Figure 203 Requesting a local certificate

6.

Retrieve the CRL:

a.

From the navigation tree, sfter retrieving a local certificate, select VPN > Certificate
Management > CRL.

b.

Click Retrieve CRL of the PKI domain of 1.

Figure 204 Retrieving the CRL

7.

Configure IKE proposal 1, using RSA signature for identity authentication:

a.

From the navigation tree, select VPN > IKE > Proposal.

b.

Click Add.

c.

Enter 1 as the IKE proposal number, select RSA Signature as the authentication method, and
click Apply.