pki get-certificate
Parameters
Parameter | Description | Value |
---|---|---|
ca | Specifies a CA or RA certificate to be obtained. | - |
local | Specifies a local certificate to be obtained. | - |
realm realm-name | Specifies the PKI realm name of a certificate to be obtained. | The value must be an existing PKI realm name. |
Usage Guidelines
Usage Scenario
When the SCEP method is used, the PKI entity queries and obtains issued certificates on the CA server and stores the certificates to the local storage. The PKI entity can download their own certificates, CA certificates, or local certificates of other entities.
- Stores certificates to the device storage to improve certificate query efficiency and reduce the times of querying the PKI certificate repository.
- Prepares for certificate authentication.
Prerequisites
A PKI realm has been created using the pki realm (system view) command.
Precautions
After obtaining a CA certificate, the device automatically imports the certificate to the device memory. After the device obtains a local certificate, you need to import it to the memory manually.
If the same certificate exists on the device, delete the existing one; otherwise, the certificate cannot be obtained.