appliance sends the certificate to the SSL peer for an SSL connection, but
the peer can reject the certificate as not valid.
Guidelines
The
password
or
password-alias
keyword is required only when a certificate file is
password-protected.
Prior to using the
password-alias
keyword, you must use the
password-map
command to 3DES-encrypt the certificate password and associate an alias with the
encrypted password. An attempt to reference an encrypted password not found in
the Password map results in command failure.
v
In environments that use plaintext (unencrypted) passwords, the
password
argument is used to open and read the certificate file.
v
In environments that use encrypted passwords, the
password-alias
argument is
searched for in the password map file and its associated encrypted password is
identified. The encrypted password, in turn, is 3DES-decrypted (using the locally
generated host key) to yield the plaintext password used to open and read the
certificate file.
Use the
certificate
command in conjunction with the
key
and
idcred
commands to
create an Identification Credentials. An Identification Credentials consists of a
certificate, which contains a public key, and the corresponding private key.
Use the
certificate
command in conjunction with the
valcred
command to create a
Validation Credentials. A Validation Credentials can be used, but is not required,
during the SSL handshake procedure to authenticate the certificate that is received
from the remote SSL peer.
The
no certificate
command deletes only the alias for the stored certificate. The file
that contains the actual certificate remains on the appliance.
Related Commands
certificate
(Crypto Validation),
copy
,
key
,
password-map
,
profile
,
valcred
Examples
v
Creates the
bob
alias for the
bob.pem
X.509 certificate. Stores the target certificate
in the public cryptographic area.
# certificate
bob pubcert:bob.pem
Creating certificate 'bob'
#
v
Creates an the
bob
alias for the
bob.pem
certificate. Stores the target certificate in
the public cryptographic area. Allows the certificate to be accessed with the
pikesville
plaintext password.
# certificate bob pubcert:bob.pem
password pikesville
Creating certificate 'bob'
#
v
Creates an the
bob
alias for the
bob.pem
certificate. Stores the target certificate in
the public cryptographic area. Allows the certificate to be accessed with the
dundaulk
encrypted password alias.
214
Command Reference
Summary of Contents for WebSphere XS40
Page 1: ...WebSphere DataPower XML Security Gateway XS40 Command Reference Version 3 7 2 ...
Page 2: ......
Page 3: ...WebSphere DataPower XML Security Gateway XS40 Command Reference Version 3 7 2 ...
Page 44: ...18 Command Reference ...
Page 194: ...168 Command Reference ...
Page 198: ...172 Command Reference ...
Page 206: ...180 Command Reference ...
Page 210: ...184 Command Reference ...
Page 222: ...196 Command Reference ...
Page 232: ...206 Command Reference ...
Page 238: ...212 Command Reference ...
Page 268: ...242 Command Reference ...
Page 272: ...246 Command Reference ...
Page 276: ...250 Command Reference ...
Page 288: ...262 Command Reference ...
Page 292: ...266 Command Reference ...
Page 298: ...272 Command Reference ...
Page 320: ...294 Command Reference ...
Page 322: ...296 Command Reference ...
Page 340: ...314 Command Reference ...
Page 344: ...318 Command Reference ...
Page 352: ...326 Command Reference ...
Page 360: ...334 Command Reference ...
Page 368: ...342 Command Reference ...
Page 376: ...350 Command Reference ...
Page 386: ...360 Command Reference ...
Page 392: ...366 Command Reference ...
Page 396: ...370 Command Reference ...
Page 402: ...376 Command Reference ...
Page 404: ...378 Command Reference ...
Page 408: ...382 Command Reference ...
Page 446: ...420 Command Reference ...
Page 450: ...424 Command Reference ...
Page 456: ...430 Command Reference ...
Page 520: ...494 Command Reference ...
Page 536: ...510 Command Reference ...
Page 550: ...524 Command Reference ...
Page 584: ...558 Command Reference ...
Page 600: ...574 Command Reference ...
Page 605: ... timeout 500 Chapter 63 RADIUS configuration mode 579 ...
Page 606: ...580 Command Reference ...
Page 650: ...624 Command Reference ...
Page 668: ...642 Command Reference ...
Page 704: ...678 Command Reference ...
Page 714: ...688 Command Reference ...
Page 726: ...700 Command Reference ...
Page 734: ...708 Command Reference ...
Page 752: ...726 Command Reference ...
Page 756: ...730 Command Reference ...
Page 804: ...778 Command Reference ...
Page 880: ...854 Command Reference ...
Page 892: ...866 Command Reference ...
Page 912: ...886 Command Reference ...
Page 918: ...892 Command Reference ...
Page 940: ...914 Command Reference ...
Page 946: ...920 Command Reference ...
Page 974: ...948 Command Reference ...
Page 1004: ...978 Command Reference ...
Page 1030: ...1004 Command Reference ...
Page 1032: ...1006 Command Reference ...
Page 1065: ......
Page 1066: ... Printed in USA ...