certificate
- system certificate
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
Digital certificates configuration
 
- system certificate scep
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
Simple Certificate Enrollment Protocol configuration
 
- system certificate scep csr <id>
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
SCEP server name
- Values:
 id – Server name (1-32)
- Instances:
 Multiple
- Required:
 - Required:
 
 
- system certificate scep csr <id> autoenrollment
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
Enable autoenrollment
 
- system certificate scep csr <id> autoenrollment retry-period <u32|id>
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
Wait period between certificate request retries
- Values:
 u32 – Time in minutes (1-999999)
N[m/h/d/w] – Time in minutes/hours/days/weeks
 
- system certificate scep csr <id> autoenrollment time <u32|id>
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
Time before certificate expiration
- Values:
 u32 – Time in minutes (1-999999)
N[m/h/d/w] – Time in minutes/hours/days/weeks
 
- system certificate scep csr <id> ca-fingerprint
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
Expected fingerprint for the CA certificate
- Instances:
 Unique
 
- system certificate scep csr <id> ca-fingerprint md5 <id>
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
MD5 fingerprint
- Values:
 id – MD5 fingerprint in hex format (16)
 
- system certificate scep csr <id> ca-fingerprint sha <id>
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
SHA fingerprint
- Values:
 id – SHA fingerprint in hex format (20)
 
- system certificate scep csr <id> ca-name <id>
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
- Values:
 id – CA name
 
- system certificate scep csr <id> cert-renew-via-renewalreq
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
Perform certificate renewal via msgType RenewalReq instead of PKCSReq
 
- system certificate scep csr <id> cgi-path <txt>
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
- Values:
 txt – CGI script path
 
- system certificate scep csr <id> challenge-password <txt>
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
Challenge password CSR request of enrollment
- Values:
 txt – Password (1-256)
 
- system certificate scep csr <id> distinguished-names <txt>
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
Comma separated list of distinguished names for the CSR
- Values:
 txt – DN (1-250)
 
- system certificate scep csr <id> dns <id>
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
Add DNS name as alternative name
- Values:
 id – Domain Name System
 
- system certificate scep csr <id> email <id>
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
Add email as alternative name
- Values:
 id – Email
 
- system certificate scep csr <id> encrypted-password <password>
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
- Values:
 password – Encrypted challenge password CSR request of enrollment
 
- system certificate scep csr <id> ip-address <ipv4|ipv6>
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
Add source IP address as alternative name
- Values:
 ipv4 – Local IPv4 address
ipv6 – Local IPv6 address
- Local IP address:
 
 
- system certificate scep csr <id> local-address <ipv4|ipv6>
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
Local IP address to use as source for SCEP requests
- Values:
 ipv4 – Local IPv4 address for csr
ipv6 – Local IPv6 address for csr
- Local IP address:
 
 
- system certificate scep csr <id> local-interface <ifc>
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
- Values:
 ifc – Interface to use as source for SCEP requests
 
- system certificate scep csr <id> local-vrf <id>
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
VRF where socket is bound
- Reference:
 
 
- system certificate scep csr <id> port <u32>
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
SCEP server port
- Values:
 u32 – Port (1-65535)
 
- system certificate scep csr <id> regenerate-key
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
Regenerate key on enrollment
 
- system certificate scep csr <id> rollover
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
Enable rollover for CA expiration
 
- system certificate scep csr <id> rollover retry-period <u32|id>
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
Wait period between rollover retries
- Values:
 u32 – Time in minutes (1-999999)
N[m/h/d/w] – Time in minutes/hours/days/weeks
 
- system certificate scep csr <id> rollover time <u32|id>
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
Time before CA expiration
- Values:
 u32 – Time in minutes (1-999999)
N[m/h/d/w] – Time in minutes/hours/days/weeks
 
- system certificate scep csr <id> rsa-key-length <u32>
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
RSA key length in bits to generate
- Values:
 u32 – Key length (512-4096)
 
- system certificate scep csr <id> serial-number
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
Add router serial number to the CSR
 
- system certificate scep csr <id> signer-names <txt>
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
Comma separated list of distinguished names for the PKCS#7 envelop
- Values:
 txt – DN (1-250)
 
- system certificate scep csr <id> url <ipv4|ipv6|txt>
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
SCEP server address
- Values:
 ipv4 – SCEP IPv4 address
ipv6 – SCEP IPv6 address
txt – SCEP hostname
 
- system certificate trust <file>
 - AresC640
Atlas840
M10-Smart
M2
RS420
RXL15000
SDE
- Values:
 file – Add a certificate to the trusted root certificates
- Instances:
 Multiple