SR OS PKI implementation supports the following features:
Supported ECDSA curves include:
secp256r1
secp384r1
secp521r1
Certificate enrollment includes:
Locally generated RSA/DSA/ECDSA key
Off-line enrollment via PKCS#10
On-line enrollment via Certificate Management Protocol version 2 (CMPv2)
Support CA chain
Certificate revocation check:
CRL for both EE (End Entity) and CA certificate
OCSP for EE certificate only