使用SCEP简化IPSec网络的密钥管理
Simplifying Key Management of IPSec Network with SCEP
IPSec(IP Security)是IETF制定的三层隧道加密协议,它为Internet上传输的数据提供了高质量的、可互操作的、基于密码学的安全保证。它提供的安全服务包括:数据机密性,数据完整性,数据来源认证及防重放。一般的IPSec网络通过手工配置密钥,不利于大规模搭建,本文描述了如何在万林克路由器上实现SCEP模块,通过向CA服务器注册证书,从而利用数字证书对密钥进行管理解决该问题。同时,文章还介绍了如何实现证书的自动注册从而进一步简化IPSec网络的密钥管理。
IPSec (IP Security) are protocols that IETF develop to provide high-quality, interoperate, cryptography-based security data transmitting, it based on the technology of three-layer tunnel cryptographic. Generally, people have to configure the key manually, which block the implement of large-scale IPSec network. This article describes how to implement SCEP module which provide the services of enrolling certificates from CA on Vanlink router, thus the use of digital certificates can be a solution to the problem. Meanwhile, this article also describes how to enroll the certificates automatically in order to further simplify the key management of IPSec network.
马跃、周炜昕
通信
IPSecSCEP数字证书服务器密钥管理
IPSecSCEPertificateKey Management
马跃,周炜昕.使用SCEP简化IPSec网络的密钥管理[EB/OL].(2009-02-20)[2025-08-04].http://www.paper.edu.cn/releasepaper/content/200902-1049.点此复制
评论