Working in the CLI
Certificate Commands
Each SSL certificate installed on Equalizer has a CLI context that provides commands for
managing the certificate and its associated private key. Certificates, private keys, and CRLs (see
the following section) are used by Equalizer to provide SSL offloading for HTTPS clusters.
In SSL offloading, Equalizer terminates the SSL connection with the client, decrypts the client
request using a certificate and key, sends the request on to the appropriate server, and encrypts
the server response before forwarding it on to the client.
Certificates are uploaded to Equalizer and then associated with one or more clusters. Two types of
certificates may be used to authenticate HTTPS cluster connections:
l
A cluster certificate is required to authenticate the cluster to the client and to decrypt the cli-
ent request (these are also called server certificates). For cluster certificates, both a cer-
tificate file and a private key file must be uploaded to Equalizer.
l
A cluster may also be configured to ask for, or require, a
client certificate
-- a certificate
used to authenticate the client to Equalizer. For client certificates, only a certificate file is
uploaded to Equalizer(no keyfile is used).
Supported certificate commands are shown in the following tables.
Using Certificate Commands in Global Context
eqcli >
certificate
certname [cmd ...]
: Create certname (
req_cmds
= * com-
mands below)
eqcli >
certificate
certname cmd ...
: Modify certname (
cmd
= any commands
below)
eqcli >
no certificate certname
: Delete
certname
eqcli >
show certificate [
certname
]
: Display all certificates or
cert-
name
eqcli >
certificate
certname
: Change to "cert-certname" context
(see below)
166
Copyright © 2014 Coyote Point Systems, A Subsidiary of Fortinet, Inc.
Summary of Contents for Equalizer GX Series
Page 18: ......
Page 32: ...Overview 32 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 42: ......
Page 52: ......
Page 64: ......
Page 72: ......
Page 76: ......
Page 228: ......
Page 238: ......
Page 476: ......
Page 492: ......
Page 530: ......
Page 614: ......
Page 626: ......
Page 638: ......
Page 678: ......
Page 732: ...Using SNMP Traps 732 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 754: ......
Page 790: ......
Page 804: ......
Page 842: ......
Page 866: ......