download ssl certificate
ExtremeWare XOS 11.5 supports only the Summit X450 family of switches and the BlackDiamond 8800 series switch.
ExtremeWare XOS 11.5 Command Reference Guide
999
download ssl certificate
download ssl <ip_address> certificate <cert file>
Description
Permits downloading of a certificate key from files stored in a TFTP server.
Syntax Description
Default
N/A.
Usage Guidelines
If the download operation is successful, any existing certificate is overwritten. After a successful
download, the software attempts to match the public key in the certificate against the private key
stored. If the private and public keys do not match, the switch displays a warning message similar to
the following:
Warning: The Private Key does not match with the Public Key in the
certificate
. This warning acts as a reminder to also download the private key.
NOTE
You can only download a certificate key in the VR-Mgmt virtual router.
Downloaded certificates and keys are not saved across switch reboots unless you save your current
switch configuration. Once you issue the save command, the downloaded certificate is stored in the
configuration file and the private key is stored in the EEPROM.
Similar to SSH2, before you can use any SSL commands, you must first download and install the
separate Extreme Networks SSH software module (ssh.xmod). This additional module allows you to
configure both SSH2 and SSL on the switch. SSL is packaged with the SSH module; therefore, if you do
not install the module, you are unable to configure SSL. If you try to execute SSL commands without
installing the module first, the switch notifies you to download and install the module. To install the
module, see the instructions in
Appendix A, “Software Upgrade and Boot Options,”
of the
ExtremeWare
XOS Concepts Guide
.
You can purchase and obtain SSL certificates from Internet security vendors.
Remote IP Address Character Restrictions.
This section provides information about the characters
supported by the switch for remote IP addresses.
ip_address
Specifies the IP address of the TFTP server.
cert file
Specifies the name of the certificate key.