[Contents] [Prev] [Next] [Index] [Report an Error]

Configuring a CA Profile with a Configuration Editor

The CA profile contains the name and the URL of the CA as well as a public key and additional information. To configure a CA profile:

  1. Navigate to the top of the configuration hierarchy in either the J-Web or the CLI configuration editor.
  2. Perform the tasks described in Table 32.
  3. Go on to Requesting a CA Certificate from a CA.

Table 32: Configuring a CA Profile

Navigate to the Security level in the configuration hierarchy.

  1. In the configuration hierarchy, click Security.
  2. Next to Security, click Configure.

From the top of the configuration hierarchy, enter

edit security pki

Add a new CA profile to the Services Router.

  1. Select Pki.
  2. Click Configure.
  3. Next to Ca profile, click Add new entry.

Configure the profile name and the CA authority identification—for example, ca-profile-ipsec and versign.com.

  1. In the Ca profile name box, type ca-profile-ipsec.
  2. In the Ca identity box, type verisign.com.
  3. Next to Enrollment, click Configure.

Enter

edit ca-profile ca-profile-ipsec ca-identity verisign.com

Configure the following enrollment options:

  • Enrollment URL—URL where the Simple Certificate Enrollment Protocol (SCEP) request is sent to the certification authority configured in this profile—for example, www.versign.com.
  • Enrollment retry—Number of attempts at online enrollment with the CA profile to allow for a router certificate, if enrollment fails—for example, 10. The range is from 0 through 100 attempts.
  • Enrollment retry-interval—Length of time, in seconds, to allow between enrollment attempts—for example, 60. The range is from 0 through 3600 seconds.
  1. In the Retry box, type 10.
  2. In the Retry interval box, type 60.
  3. In the Url box, type www.verisign.com.
  4. Click OK.

Enter

edit ca-profile ca-profile-ipsec ca-identity versign.com enrollment url http://www.verisign.com retry 10 retry-interval 60


[Contents] [Prev] [Next] [Index] [Report an Error]