功能简介
简单证书注册协议(SCEP)是一种行业标准协议和技术。它主要通过企业的内部 CA 为设备颁发证书,能够安全可靠地为设备在线提供数字证书。
网页配置
进入网页界面,前往 安全 -> SCEP。
参数配置
static.scep.enable
static.scep.url
static.scep.user
static.scep.password
static.scep.enroll.retry_count
static.scep.enroll.retry_interval
static.scep.renewal.threshold
static.scep.renewal.time
static.scep.challenge_password
static.scep.csr.common_name
static.scep.csr.organization
static.scep.csr.email
static.scep.csr.state
static.scep.csr.country
M语句
可选值
出厂默认值
功能描述
static.scep.enable
0-Disabled1-Enabled
0
配置是否使用SCEP获取/更新证书。
static.scep.url
256个字符以内
空
配置SCEP服务器的地址,有更新则会触发获取证书流程。
static.scep.user
256个字符以内
空
配置SCEP服务器的用户名称。
static.scep.password
256个字符以内
空
配置SCEP服务器的密码。
static.scep.enroll.retry_count
从1到12的整数
3
配置话机注册到SCEP服务器错误/等待(包括证书获取失败)的重试次数。
static.scep.enroll.retry_interval
从300到3600的整数
300
配置话机注册到SCEP服务器错误/等待(包括证书获取失败)的重试间隔秒数。
static.scep.renewal.threshold
从50到100的整数
80
配置话机从SCEP服务器发起更新时证书有效期的百分比。
static.scep.renewal.time
前两位数字代表时钟:00 至 23;
后两位数字代表分钟:00 至 59;
100
配置话机向SCEP服务器发起证书更新的开始时间点,接下去十五分钟内,话机随机开始证书更新。
static.scep.challenge_password
256个字符以内
空
配置话机与SCEP服务器请求证书时的验证密码。
static.scep.csr.common_name
64个字符以内
空
配置用于生成CSR的通用名称;备注:服务器的标准域名(FQDN)。这必须与在Web浏览器中键入的内容完全匹配,否则将收到名称不匹配错误。
static.scep.csr.organization
64个字符以内
空
配置用于生成CSR的组织的法定名称;备注:不应缩写,并且应包括Inc,Corp或LLC之类的后缀
static.scep.csr.email
64个字符以内
空
配置用于生成CSR的邮箱地址
static.scep.csr.state
64个字符以内
空
配置用于生成CSR的州/省名称;备注:不应该缩写。
static.scep.csr.country
2个字符以内
空
配置用于生成CSR的国家名称;备注:组织所在国家/地区的两个字母的ISO代码。