Submitting a certificate request in auto mode


[IMPORTANT: ]

IMPORTANT:

In auto mode, an entity does not automatically re-request a certificate to replace a certificate that is expiring or has expired. After the certificate expires, the service using the certificate might be interrupted.


In auto request mode, an entity automatically requests a certificate from the CA when an application works with the PKI entity that does not have a local certificate. The entity saves the local certificate after retrieving it from the CA.

A CA certificate must be present before you request a local certificate. If no CA certificate exists in the PKI domain, the PKI entity automatically obtains a CA certificate before sending a certificate request.

To configure an entity to submit a certificate request in auto mode:

Step

Command

Remarks

1. Enter system view.

system-view

N/A

2. Enter PKI domain view.

pki domain domain-name

N/A

3. Set the certificate request mode to auto.

certificate request mode auto [ key-length key-length | password { cipher | simple } password ] *

Manual by default.