N in, Figure 11 – H3C Technologies H3C SecPath F1000-E User Manual
Page 156
9
Figure 11 Add a PKI domain
•
Type 1 as the PKI domain name.
•
Type CA server as the CA identifier.
•
Select en as the local entity.
•
Select RA as the authority for certificate request.
•
Type http://10.1.2.2/certsrv/mscep/mscep.dll as the URL for certificate request.
•
Click Apply. Then, click OK when the system displays “Fingerprint of the root certificate not
specified. No root certificate validation will occur. Continue?”
# Generate an RSA key pair.
•
Select VPN > PKI > Certificate from the navigation tree and then click Create Key to perform
the configurations as shown in
.
Figure 12 Generate an RSA key pair
•
Click Apply to generate an RSA key pair.
# Retrieve the CA certificate.
•
Select VPN > PKI > Certificate from the navigation tree and then click Retrieve Cert to
perform the configurations as shown in
.