Verifying the configuration, Configuration guidelines – H3C Technologies H3C WX3000E Series Wireless Switches User Manual

Page 397

Advertising
background image

384

Verifying the configuration

After the configuration, you can select Authentication > PKI from the navigation tree and click the

Certificate tab to view detailed information about the retrieved CA certificate and the local certificate, or
select click the CRL tab to view detailed information about the retrieved CRL.

Configuration guidelines

When you configure PKI, note the following guidelines:

Make sure the clocks of entities and the CA are synchronous. Otherwise, the validity period of

certificates will be abnormal.

The Windows 2000 CA server has some restrictions on the data length of a certificate request. If the
PKI entity identity information in a certificate request goes beyond a certain limit, the server will not

respond to the certificate request.

The SCEP plug-in is required when you use the Windows Server as the CA. In this case, you need
to specify RA as the authority for certificate request when configuring the PKI domain.

The SCEP plug-in is not required when you use the RSA Keon software as the CA. In this case, you
need to specify CA as the authority for certificate request when configuring the PKI domain.

Advertising