Operation Manual – PKIH3C S3610&S5510 Series Ethernet Switches Chapter 1 PKI Configuration1-9Follow these steps to configure an entity to submit a certificate request in auto mode:To do… Use the command… RemarksEnter system view system-view —Enter PKI domain view pki domain domain-name —Set the certificate requestmode to autocertificate request mode auto[ key-length key-length | password{ cipher | simple } password ] *RequiredManual bydefault1.5.2 Submitting a Certificate Request in Manual ModeIn manual mode, you need to retrieve a CA certificate, generate a local RSA key pair,and submit a local certificate request for an entity.The goal of retrieving a CA certificate is to verify the authenticity and validity of a localcertificate.Generating an RSA key pair is an important step in certificate request. The key pairincludes a public key and a private key. The private key is kept by the user, while thepublic key is transferred to the CA along with some other information. For detailedinformation about RSA key pair configuration, refer to SSH Configuration.Follow these steps to submit a certificate request in manual mode:To do… Use the command… RemarksEnter system view system-view —Enter PKI domain view pki domain domain-name —Set the certificate requestmode to manualcertificate request modemanualOptionalManual by defaultReturn to system view quit —Retrieve a CA certificatemanuallyRefer to Retrieving aCertificate Manually RequiredGenerate a local RSA keypair public-key local create rsaRequiredNo local RSA key pairexists by default.Submit a local certificaterequestpki request-certificatedomain domain-name[ password ] [ pkcs10[ filename filename ] ]Required