No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search


To have a better experience, please upgrade your IE browser.


Fat AP and Cloud AP V200R010C00 Command Reference

Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
pki get-certificate

pki get-certificate


The pki get-certificate command downloads a certificate to the device storage.


pki get-certificate { ca | local } realm realm-name


Parameter Description Value
ca Specifies a CA or RA certificate to be obtained. -
local Specifies a local certificate to be obtained. -
realm realm-name Specifies the PKI realm name of a certificate to be obtained. The value must be an existing PKI realm name.


System view

Default Level

2: Configuration level

Usage Guidelines

Usage Scenario

When the SCEP method is used, the PKI entity queries and obtains issued certificates on the CA server and stores the certificates to the local storage. The PKI entity can download their own certificates, CA certificates, or local certificates of other entities.

The purposes of obtaining a certificate are as follows:
  • Stores certificates to the device storage to improve certificate query efficiency and reduce the times of querying the PKI certificate repository.
  • Prepares for certificate authentication.


A PKI realm has been created using the pki realm (system view) command.


After obtaining a CA certificate, the device automatically imports the certificate to the device memory. After the device obtains a local certificate, you need to import it to the memory manually.

If the same certificate exists on the device, delete the existing one; otherwise, the certificate cannot be obtained.


# Obtain the CA certificate in the PKI realm abc.

<Huawei> system-view
[Huawei] pki realm abc
[Huawei-pki-realm-abc] quit
[Huawei] pki get-certificate ca realm abc
Updated: 2019-11-21

Document ID: EDOC1100064352

Views: 207948

Downloads: 122

Average rating:
This Document Applies to these Products
Related Version
Related Documents
Previous Next