Configuring Secure Socket Layer (SSL)
Configuring the Switch for SSL Operation
CLI commands used to generate a Server Host Certificate.
Syntax:
crypto key generate cert [rsa] < 512 | 768 |1024 >
Generates a key pair for use in the certificate.
crypto key zeroize cert
Erases the switch’s certificate key and disables SSL opera
tion.
crypto host-cert generate self-signed [arg-list]
Generates a self signed host certificate for the switch. If a
switch certificate already exists, replaces it with a new
certificate. (See the Note, above.)
crypto host-cert zeroize
Erases the switch’s host certificate and disables SSL opera
tion.
To generate a host certificate from the CLI:
i.
Generate a certificate key pair. This is done with the
crypto key
generate cert
command. The default key size is 512.
N o t e
If a certificate key pair is already present in the switch, it is not necessary to
generate a new key pair when generating a new certificate. The existing key
pair may be re-used and the crypto key generate cert command does not have
to be executed.
ii. Generate a new self-signed host certificate. This is done with the
crypto host-cert generate self-signed [
Arg-List]
command.
N o t e
When generating a self-signed host certificate on the CLI if there is not
certificate key generated this command will fail.
Comments on Certificate Fields.
There are a number arguments used in the generation of a server certificate.
table 8-1, “Certificate Field Descriptions” describes these arguments.
8-10
Summary of Contents for PROCURVE 2910AL
Page 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Page 2: ......
Page 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Page 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Page 156: ...TACACS Authentication Operating Notes 4 30 ...
Page 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Page 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Page 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Page 592: ...12 Index ...
Page 593: ......