Parameter | Description | Value |
---|---|---|
ca | Specifies a CA or RA certificate to be obtained. | - |
realm realm-name | Specifies the PKI realm name of a certificate to be obtained. | The value must be an existing PKI realm name. |
Usage Scenario
When you request a local certificate for the PKI entity through SCEP, run this command to download a CA certificate to the device storage, and request a local certificate using the encrypted CA public key.
Prerequisites
A PKI realm has been created using the pki realm (system view) command.
Precautions
After obtaining a CA certificate, the device automatically imports the certificate to the device memory.
If the same certificate exists on the device, delete the existing one; otherwise, the certificate cannot be obtained.