Parameter
Description
<certname>
Name of the signer certificate.
<filename>
Original imported filename of the signer certificate.
TrustedCA
Trusted CA certificate. This can be either a root CA or intermediate CA. Dell encourages
(but does not require) an intermediate CA’s signing CA to be the controller itself.
<certname>
Name of the signer certificate.
<filename>
Original imported filename of the signer certificate.
global-ocsp-signer-cert
Specifies the global OCSP signer certificate to use when signing OCSP responses if
there is no check point specific OSCP signer certificate present. If the ocsp-signer-cert
is not specified, OCSP responses are signed using the global OCSP signer certificate. If
this is not present, than an error message is sent out to clients.
NOTE: The OCSP signer certificate (if configured) takes precedence over the global
OCSP signer certificate as this is check point specific.
rcp <name>
Specifies the revocation check point. A revocation checkpoint is automatically created
when a TrustedCA or IntermediateCA certificate is imported on the controller.
service-ocsp-responder
This is a global knob that turns the OCSP responder on or off. The default is off
(disabled). To enable this option a CRL must be configured for this revocation checkpoint
as this is the source of revocation information in the OCSP responses.
Usage Guidelines
This command lets you configure the controller to perform real-time certificate revocation checks using the Online
Certificate Status Protocol (OCSP) or traditional certificate validation using the Certificate Revocation List (CRL)
client. Refer to the
Certificate Revocation
chapter in the
Dell PowerConnect W-Series ArubaOS 6.2 User Guide
for
more information on how to configure this feature using both the WebUI and CLI.
Example
This example configures the controller as an OCSP responder.
The revocation check point is specified as CAroot. (The revocation check point CAroot was automatically created
when the CAroot certificate was previously uploaded to this controller.) The OCSP signer certificate is RootCA-
Ocsp_signer. The CRL file is Security1-WIN-05PRGNGEKAO-CA-unrevoked.crl The OCSP responder is enabled.
crypto-local pki service-ocsp-responder
crypto-local pki rcp CARoot
ocsp-signer-cert RootCA-Ocsp_signer
crl-location file Security1-WIN-05PRGNGEKAO-CA-unrevoked.crl
enable-ocsp-responder
Related Commands
Command
Description
Mode
crypto-local pki rcp
Specifies the certificates that are used to sign OCSP
responses for this revocation check point
Config mode
show crypto-local pki
This command shows local certificate, OCSP signer or
responder certificate and CRL data and statistics.
Config mode
Dell PowerConnect W-Series ArubaOS 6.2 |
Reference Guide
crypto-local pki | 231
Summary of Contents for PowerConnect W-7200 Series
Page 1: ...Dell PowerConnect W Series ArubaOS 6 2 Command Line Interface Reference Guide ...
Page 38: ...38 aaa authentication server windows DellPowerConnect W Series ArubaOS 6 2 Reference Guide ...
Page 319: ...DellPowerConnect W Series ArubaOS 6 2 Reference Guide interface loopback 319 ...
Page 346: ...346 ipv6 mld DellPowerConnect W Series ArubaOS 6 2 Reference Guide ...
Page 387: ...DellPowerConnect W Series ArubaOS 6 2 Reference Guide ip radius 387 ...
Page 995: ...DellPowerConnect W Series ArubaOS 6 2 Reference Guide show firewall 995 ...
Page 1529: ...DellPowerConnect W Series ArubaOS 6 2 Reference Guide wms client 1529 ...
Page 1536: ...0510956 01 March 2013 1536 ...