447
Examples
# Specify 2048-bit DSA key pair
abc
for certificate request.
<Sysname> system-view
[Sysname] pki domain aaa
[Sysname-pki-domain-aaa] public-key dsa name abc length 2048
Related commands
pki import
public-key local create
(see
Security Command Reference
)
public-key ecdsa
Use
public-key ecdsa
to specify an ECDSA key pair for certificate request.
Use
undo public-key
to restore the default.
Syntax
In non-FIPS mode:
public-key ecdsa name
key-name
[
secp192r1
|
secp256r1
|
secp384r1
]
undo public-key
In FIPS mode:
public-key ecdsa name
key-name
[
secp256r1
|
secp384r1
]
undo public-key
Default
No key pair is specified for certificate request.
Views
PKI domain view
Predefined user roles
network-admin
Parameters
name
key-name
: Specifies a key pair by its name, a case-insensitive string of 1 to 64 characters.
The key pair name can contain only letters, digits, and hyphens (-).
secp192r1
: Uses the secp192r1 curve to generate the key pair. The secp192r1 curve is used by
default in non-FIPS mode.
secp256r1
: Uses the secp256r1 curve to generate the key pair. The secp256r1 curve is used by
default in FIPS mode.
secp384r1
: Uses the secp384r1 curve to generate the key pair.
Usage guidelines
You can specify a nonexistent key pair for a PKI domain.
A key pair can be obtained in any of the following ways:
•
Use the
public-key local create
command to generate a key pair.
•
An application, like IKE using digital signature authentication, triggers the device to generate a
key pair.
•
Use the
pki import
command to import a certificate containing a key pair.
Summary of Contents for FlexNetwork MSR Series
Page 1005: ...987 ...