No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

FAQ-Why Does Certification Application Succeed in Code Mode But Fail in Certificate Signature Mode for IPSec?

Publication Date:  2019-01-24 Views:  47 Downloads:  0
Issue Description
Why does certification application succeed in code mode but fail in certificate signature mode for IPSec?
Solution
Compared with the code mode, the certificate signature mode experiences more strict examination on the obtained certificate and requires the IP address and FQDN configuration on the entity.
For example, the key configuration in code mode is as follows:
#
pki entity huawei-code
country BE
organization belgacom
common-name huaweicode
The key configuration in certificate signature mode is as follows:
#
pki entity huawei-code
country BE
organization belgacom
common-name huaweicmp
fqdn huawei.com.cn
ip-address 192.168.0.161

END