as shown in a. Then, click Apply to destroy the existing RSA key pair and the corresponding local certificate.

a.Key pair destruction page

Return to Configuration task list for requesting a certificate manually.

Return to Configuration task list for requesting a certificate automatically.

Retrieving a certificate

You can download an existing CA certificate or local certificate from the CA server and save it locally. To do so, you can use two ways: online and offline. In offline mode, you need to retrieve a certificate by an out-of-band means like FTP, disk, e-mail and then import it into the local PKI system.

Select Authentication PKI from the navigation tree, and then select the Certificate tab to enter the page displaying existing PKI certificates, as shown in a. Click Retrieve Cert to enter PKI certificate retrieval page, as shown in a.

a.PKI certificate retrieval page

2.Configuration items for retrieving a PKI certificate

Item

Description

Domain Name

Select the PKI domain for the certificate.

 

 

Certificate Type

Select the type of the certificate to be retrieved, which can be CA or local.

 

 

Enable Offline

Select this check box to retrieve a certificate in offline mode (that is, by an out-of-band

means like FTP, disk, or e-mail) and then import the certificate into the local PKI system.

Mode

The following configuration items are displayed if this check box is selected.

 

 

 

Get File From

Specify the path and name of the certificate file.

Device

 

 

 

393