3Com Switch 8800 Family IPsec Module Configuration and Command reference Guide
438 CHAPTER 24: PKI CONFIGURATION COMMANDS
Parameter
domain-name: Domain name containing CA or RA related information. It is
configured by using the pki domain command.
password: Password for revoking certificates, an optional string in the range of
one character to 31 characters.
pkcs10: Displays on the terminal the request for PKCS#10 certificates in BASE64
codes. This information is used in the certificate requests in outband modes such
as phone, disk, and e-mail.
filename: Target file to save the PKCS#10 certificate request.
Description
Use the pki request-certificate command to deliver certificate request through
SCEP to CA for the generated RSA key pair. If SCEP fails to go through normal
communication, you can print the local certificate request in base64 format using
the optional parameter "pem", copy it, and send one to CA in an outband mode.
This operation is not saved within the configuration.
Related command: pki domain.
Example
# Manually apply for a certificate and display on the terminal the PKCS#10
certificate request.
[SecBlade_VPN] pki request-certificate domain 1 pkcs10
pki retrieval-certificate Syntax
pki retrieval-certificate { local | ca } domain domain-name
View
System view
Parameter
local: Downloads local certificates;
ca: Downloads CA certificates;
domain-name: Domain name containing CA or RA related information. It is
configured by using the pki domain command.
Description
Use the pki retrieval-certificate command to download a certificate from the
certificate issuing server.
Related command: pki domain.
Example
# Retrieve a certificate
[SecBlade_VPN] pki retrieval-certificate ca domain 1