Replacing the Default Certificate, Key, and Cipherspec
Using Equalizer's Remote Management commands in the CLI, you can replace the default
certificate, key, and cipher spec that are used with HTTPS services on subnets with custom
certificates, keys and cipher specs.
The process includes:
l
Uploading the custom certificate and key file to the file store.
l
Entering the certificate (and key file) to be used with HTTPS services.
l
Replacing the default cipherspec with the a custom cipher spec.
l
Setting the encryption level to use in the communications between the client and the ADC.
Uploading the Custom Certificate and Key File
Enter the following to upload a certificate and key file:
1. Enter the name of the new certificate and upload it as follows:
eqcli >
certificate
certificatename
certfile
URL
where
URL
downloads the
certfile
using
ftp://
or
http://
protocol.
2. Upload the new key file. The key file must have the same name as the certificate.
eqcli >
certificate
certificatename
keyfile
URL
where
URL
downloads the
keyfile
using
ftp://
or
http://
protocol.
Copyright © 2014 Coyote Point Systems, A Subsidiary of Fortinet, Inc.
All Rights Reserved.
61
Equalizer Administration Guide
Summary of Contents for Equalizer GX Series
Page 18: ......
Page 32: ...Overview 32 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 42: ......
Page 52: ......
Page 64: ......
Page 72: ......
Page 76: ......
Page 228: ......
Page 238: ......
Page 476: ......
Page 492: ......
Page 530: ......
Page 614: ......
Page 626: ......
Page 638: ......
Page 678: ......
Page 732: ...Using SNMP Traps 732 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 754: ......
Page 790: ......
Page 804: ......
Page 842: ......
Page 866: ......