526
Fabric OS Administrator’s Guide
53-1001763-02
FIPS mode configuration
D
LDAP certificates for FIPS mode
To utilize the LDAP services for FIPS between the switch and the host, you must generate a CSR on
the Active Directory server and import and export the CA certificates. To support server certificate
validation, it is essential to have the CA certificate installed on the switch and Active Directory
server. Use the secCertUtil to import the CA certificate to the switch. This will prompt for the remote
IP and login credentials to retrieve the CA certificate. The CA certificate should be in any of the
standard certificate formats, “.cer”, ”.crt” or “.pem”.
For storing and obtaining CA certificates, follow the instructions earlier in this section. LDAP CA
certificate file names should not contain spaces while using the secCertUtil command to import
and export the certificate.
Importing an LDAP switch certificate
This option imports the LDAP CA certificate from the remote host to the switch.
1. Connect to the switch and log in as admin.
2. Enter the secCertUtil import -ldapcacert command.
Example of importing an LDAP certificate
switch:admin>
seccertutil import -ldapcacert
Select protocol [ftp or scp]:
scp
Enter IP address:
192.168.38.206
Enter remote directory:
/users/aUser/certs
Enter certificate name (must have ".crt" or ".cer" ".pem" suffix):
LDAPTestCa.cer
Enter Login Name:
aUser
Password:
<hidden>
Success: imported certificate [LDAPTestCa.cer].
Exporting an LDAP switch certificate
This option exports the LDAP CA certificate from the switch to the remote host.
1. Connect to the switch and log in as admin.
2. Enter the secCertUtil export -ldapcacert command.
Example of exporting an LDAP CA certificate
switch:admin>
seccertutil export -ldapcacert
Select protocol [ftp or scp]:
scp
Enter IP address:
192.168.38.206
Enter remote directory:
/users/aUser/certs
Enter Login Name:
aUser
Enter LDAP certificate name (must have ".pem" \ suffix):
LDAPTestCa.ce
r
Password:
<hidden>
Success: exported LDAP certificate
Summary of Contents for 53-1001763-02
Page 1: ...53 1001763 02 13 September 2010 Fabric OS Administrator s Guide Supporting Fabric OS v6 4 0 ...
Page 4: ...iv Fabric OS Administrator s Guide 53 1001763 02 ...
Page 24: ...xxiv Fabric OS Administrator s Guide 53 1001763 02 ...
Page 28: ...xxviii Fabric OS Administrator s Guide 53 1001763 02 ...
Page 32: ...xxxii Fabric OS Administrator s Guide 53 1001763 02 ...
Page 40: ...xl Fabric OS Administrator s Guide 53 1001763 02 ...
Page 42: ...2 Fabric OS Administrator s Guide 53 1001763 02 ...
Page 54: ...14 Fabric OS Administrator s Guide 53 1001763 02 High availability of daemon processes 1 ...
Page 74: ...34 Fabric OS Administrator s Guide 53 1001763 02 Basic connections 2 ...
Page 102: ...62 Fabric OS Administrator s Guide 53 1001763 02 Audit log configuration 3 ...
Page 214: ...174 Fabric OS Administrator s Guide 53 1001763 02 Management interface security 7 ...
Page 228: ...188 Fabric OS Administrator s Guide 53 1001763 02 Brocade configuration form 8 ...
Page 276: ...236 Fabric OS Administrator s Guide 53 1001763 02 Creating a logical fabric using XISLs 10 ...
Page 404: ...364 Fabric OS Administrator s Guide 53 1001763 02 ...
Page 440: ...400 Fabric OS Administrator s Guide 53 1001763 02 Performance data collection 17 ...
Page 480: ...440 Fabric OS Administrator s Guide 53 1001763 02 F_Port masterless trunking 19 ...
Page 494: ...454 Fabric OS Administrator s Guide 53 1001763 02 Buffer credit recovery 20 ...
Page 574: ...534 Fabric OS Administrator s Guide 53 1001763 02 Hexadecimal overview E ...