216
Fabric OS Administrator’s Guide
53-1002745-02
Authentication policy for fabric elements
7
Exporting the CSR for FCAP
You will need to export the CSR file created in
“Generating the key and CSR for FCAP”
section and
send to a Certificate Authority (CA). The CA will in turn provide two files as outlined in
“FCAP
configuration overview”
on page 215.
1. Log in to the switch using an account with admin permissions, or an account associated with
the chassis role and having OM permissions for the PKI RBAC class of commands.
2. Enter the secCertUtil export –fcapswcsr command.
switch:admin>
seccertutil export -fcapswcsr
Select protocol [ftp or scp]:
scp
Enter IP address: 10.1.2.3
Enter remote directory:
/myHome/jdoe/OPENSSL
Enter Login Name:
jdoe
[email protected]'s password:
<hidden text>
Success: exported FCAP CA certificate
Importing CA for FCAP
Once you receive the files back from the Certificate Authority, you will need to install or import them
onto the local and remote switches.
1. Log in to the switch using an account with admin permissions, or an account associated with
the chassis role and having OM permissions for the PKI RBAC class of commands.
2. Enter the secCertUtil import –fcapcacert command and verify the CA certificates are
consistent on both local and remote switches.
switch:admin>
seccertutil import -fcapcacert
Select protocol [ftp or scp]:
scp
Enter IP address:
10.1.2.3
Enter remote directory:
/myHome/jdoe/OPENSSL
Enter certificate name (must have a ".pem" suffix):
CACert.pem
Enter Login Name:
jdoe
[email protected]'s password:
<hidden text>
Success: imported certificate [CACert.pem].
Importing the FCAP switch certificate
ATTENTION
The CA certificates must be installed prior to installing the switch certificate.
1. Log in to the switch using an account with admin permissions, or an account associated with
the chassis role and having OM permissions for the PKI RBAC class of commands.
2. Enter the secCertUtil import –fcapswcert command.
switch:admin>
seccertutil import -fcapswcert
Select protocol [ftp or scp]:
scp
Enter IP address:
10.1.2.3
Enter remote directory:
/myHome/jdoe/OPENSSL
Enter certificate name (must have ".crt" or ".cer" ".pem" or ".psk"
suffix):
01.pem
Enter Login Name:
jdoe
[email protected]'s password:
<hidden text>
Success: imported certificate [01.pem].
Summary of Contents for Fabric OS 7.1.0
Page 1: ...53 1002745 02 25 March 2013 Fabric OS Administrator s Guide Supporting Fabric OS 7 1 0 ...
Page 24: ...24 Fabric OS Administrator s Guide 53 1002745 02 ...
Page 28: ...28 Fabric OS Administrator s Guide 53 1002745 02 ...
Page 32: ...32 Fabric OS Administrator s Guide 53 1002745 02 ...
Page 42: ...42 Fabric OS Administrator s Guide 53 1002745 02 ...
Page 132: ...132 Fabric OS Administrator s Guide 53 1002745 02 Frame Redirection 4 ...
Page 194: ...194 Fabric OS Administrator s Guide 53 1002745 02 Ports and applications used by switches 6 ...
Page 254: ...254 Fabric OS Administrator s Guide 53 1002745 02 Brocade configuration form 8 ...
Page 274: ...274 Fabric OS Administrator s Guide 53 1002745 02 Validating a firmware download 9 ...
Page 302: ...302 Fabric OS Administrator s Guide 53 1002745 02 Creating a logical fabric using XISLs 10 ...
Page 344: ...344 Fabric OS Administrator s Guide 53 1002745 02 Concurrent zone transactions 11 ...
Page 374: ...374 Fabric OS Administrator s Guide 53 1002745 02 Setting up TI over FCR sample procedure 12 ...
Page 462: ...462 Fabric OS Administrator s Guide 53 1002745 02 ...
Page 490: ...490 Fabric OS Administrator s Guide 53 1002745 02 Ports on Demand 18 ...
Page 498: ...498 Fabric OS Administrator s Guide 53 1002745 02 Supported topologies for ICL connections 19 ...
Page 626: ...626 Fabric OS Administrator s Guide 53 1002745 02 Preparing a switch for FIPS B ...
Page 630: ...630 Fabric OS Administrator s Guide 53 1002745 02 Hexadecimal Conversion C ...
Page 666: ...666 Fabric OS Administrator s Guide 53 1002745 02 ...