How do I configure a PKI certificate authority profile?

Steps

Note: The displayed parameters vary depending on the NE type, release, and the settings of other parameters.

 

Choose Administration→Security→NE PKI Authentication→PKI Certificate Authority Profiles from the NFM-P main menu. The PKI Certificate Authority Profiles form opens.


Click Create. The Certificate Authority Profile (Create) form opens.


Configure the required parameters.


Click on the CMPv2 tab and configure the required parameters.


To create a CMP key, perform the following steps.

Note: A key that is created locally on an NE, for example, using a CLI, is not sent to the NFM-P, and is displayed on the Certificate Authority Profile form as N/A. Any N/A keys on an NE must be deleted before the profile can be distributed to the NE.

  1. Click Create. The CMP Key List (Create) form opens.

  2. Configure the parameters.

  3. Save your changes and close the form.


To configure automatic CRL file download, perform the following.

  1. Click on the Auto CRL Update tab and click Create. The Auto CRL Update form opens.

  2. Configure the required parameters.

  3. To specify a URL for the CRL file, click on the Create button in the URL entries panel and configure the parameters in the CRL URL Entry form. See How do I create a file transmission profile? for information about creating a file transmission profile to use with the CRL URL entry.

  4. Save your changes and close the form.


Click Apply to save your changes.


Distribute the policy to NEs, as required.


Close the open forms.

End of steps