Submitting a certificate request in auto mode



In auto mode, an entity does not automatically re-request a certificate to replace a certificate that is expiring or has expired. After the certificate expires, the service using the certificate might be interrupted.

In auto mode, an entity automatically requests a certificate from the CA server through SCEP if it has no local certificate for an application working with PKI, and then retrieves the certificate and saves the certificate locally. Before requesting a certificate, if the PKI domain does not have the CA certificate yet, the entity automatically retrieves the CA certificate.

To configure an entity to submit a certificate request in auto mode:




1. Enter system view.



2. Enter PKI domain view.

pki domain domain-name


3. Set the certificate request mode to auto.

certificate request mode auto [ key-length key-length | password { cipher | simple } password ] *

Manual by default