C H A P T E R
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
34-1
Cisco MDS 9000 Family CLI Configuration Guide
OL-16184-01, Cisco MDS SAN-OS Release 3.x
34
Configuring Certificate Authorities and Digital
Certificates
Public Key Infrastructure (PKI) support provides the means for the Cisco MDS 9000 Family switches to
obtain and use digital certificates for secure communication in the network. PKI support provides
manageability and scalability for IPsec/IKE and SSH.
This chapter includes the following sections:
•
About CAs and Digital Certificates, page 34-1
•
Configuring CAs and Digital Certificates, page 34-5
•
Example Configurations, page 34-15
•
Maximum Limits, page 34-37
•
Default Settings, page 34-38
About CAs and Digital Certificates
This section provides information about certificate authorities (CAs) and digital certificates, and
includes the following topics:
•
Purpose of CAs and Digital Certificates, page 34-2
•
Trust Model, Trust Points, and Identity CAs, page 34-2
•
RSA Key-Pairs and Identity Certificates, page 34-2
•
Multiple Trusted CA Support, page 34-3
•
PKI Enrollment Support, page 34-4
•
Manual Enrollment Using Cut-and-Paste Method, page 34-4
•
Multiple RSA Key-Pair and Identity CA Support, page 34-4
•
Peer Certificate Verification, page 34-4
•
CRL Downloading, Caching, and Checking Support, page 34-5
•
OCSP Support, page 34-5
•
Import and Export Support for Certificates and Associated Key Pairs, page 34-5