
3-62
Initial Setup of the ProCurve NAC 800
Digital Certificates
4.
Restart the HTTPS server.
As an optional final task, you might transfer the self-signed certificate off the
NAC 800 and install it as a trusted CA root certificate on endpoints.
As you must complete these tasks, you must access the root command line
for the NAC 800’s OS:
1.
Open an SSH session with the NAC 800.
2.
Log in:
•
username =
root
•
password =
<
root password
>
Generate the Self-Certificate and Key
When keytool generates a public/private keypair, the utility automatically
creates a self-signed certificate around the public key. Follow these steps:
1.
Log in to the NAC 800 as root.
2.
Move to the
/usr/local/nac/keystore
directory.
ProCurve NAC 800:/# cd /usr/local/nac/keystore
3.
Enter this command:
4.
For example:
ProCurve NAC 800:/usr/local/nac/keystore:# keytool
-genkey -alias mynac.procurve.com -keyalg RSA
-keystore compliance.keystore
5.
When prompted, enter
changeit
for
the keystore password. You must
enter this password.
6.
Next you are prompted to enter information that will be included in the
certificate that uses this key. For the first and last name, enter the NAC
800’s FQDN.
Syntax:
keytool -genkey -alias <
keyname
> -keyalg [rsa | dsa] -keystore compli-
ance.keystore
Replace
<
keyname
>
with a name that you choose for the key’s alias
in the
compliance.keystore
file. Make a note of the name: you will
need it when you generate a certificate request or self-signed
certificate that uses this keypair.
The asymmetric algorithms supported by the NAC 800 for the
keypair include RSA and DSA; choose one or the other for the
-keyalg
option.
Summary of Contents for 800
Page 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Page 2: ......
Page 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Page 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Page 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Page 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Page 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Page 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Page 380: ...A 26 Appendix A Glossary ...
Page 394: ...B 14 Appendix B Linux Commands Service Commands ...
Page 405: ......