其它文章
思科三层交换配置清单与案例
PBX能与思科3640路由器一起使用?
如何解决bgp路由在igp路由表中抖动的问题
配置ios ca server时需要注意的cdp-url问题
配置cisco vpn client使用scep从ios router ca获取证书
配置CiscoVLAN、VLANTrunk、VTP和STP
Catalyst 2948G-L3 和 Catalyst 4908G-L3的 BVI 溢流增强功能
简单的路由协议分析和配置
cisco switch命令大全
Catalyst 4006交换机的配置实例
Cisco技术 / Cisco技术 / 配置实例 / 证书certificate生成和验证的过程

证书certificate生成和验证的过程

作者:     http://cisco.ccxx.net

1.device generates a request(PKCS#10), encrypt it with its private key, then sends it to CA in ASN message format, also include PKCS#10
PKCS#10:
device info
key size
device public key
( challenge password)

CA info:
serial no.
available date of certificate
CA public key
HMAC algorithm
CRL location

2.CA generate a random HMAC symmetric key

                                                                                                  HMAC function
3.PKCS#10 + CA info + random HMAC symmetric key----------------------------->HMAC

signature                                                                                        RSA Algorithm
4.random HMAC symmetric key + CA private key------------------------->encrypted HMAC symmetric key

5.a certificate includes:
PKCS#10 (device info, key size, device public key, challenge password)
CA info (serial no., available date, CA public key, HMAC algorithm, CRL)
HMAC signature
encrypted HMAC symmetric key
CA sends this certificate to the device which send the request(PKCS#10) to CA


 

点击在新窗口中浏览此图片



6.after receiving the certificate.
                                                                                                                        RSA alogorithm
encrypted HMAC symmetric key + CA public key(included in CA info)-----------------------------> random HMAC symmetric key generated by CA

                                                                                                                             HMAC function
7.PKCS#10 + CA info + random HMAC symmetric key computed just now----------------------->HMAC signature

8.whether the HMAC signature received from CA and the HMAC signature computed just now by device are same or not


 

点击在新窗口中浏览此图片

收藏本页

共 0 人推荐文章 证书certificate生成和验证的过程

Copyright © 2006 cisco.ccxx.net 版权所有.提供Cisco技术,Cisco培训,CCNA,CCNP,CCIE培训,Cisco论坛CCIE实验室
上海地区Cisco培训、CCNA培训、CCNP培训、CCIE培训