S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
34-10
Cisco MDS 9000 Family CLI Configuration Guide
OL-16184-01, Cisco MDS SAN-OS Release 3.x
Chapter 34 Configuring Certificate Authorities and Digital Certificates
Configuring CAs and Digital Certificates
Note
You must authenticate the CA before configuring certificate revocation checking.
To configure certificate revocation checking methods, follow these steps:
Generating Certificate Requests
You must generate a request to obtain identity certificates from the associated trust point CA for each of
your switch’s RSA key-pairs. You must then cut and paste the displayed request into an e-mail message
or in a website form for the CA.
Command
Purpose
Step 1
switch(config)#
crypto ca trustpoint admin-ca
switch(config-trustpoint)#
Declares a trust point CA that the switch
should trust and enters trust point
configuration submode.
Step 2
switch(config-trustpoint)#
ocsp url
http://crlcheck.cisco.com
Specifies the for OCSP to use to check for
revoked certificates.
switch(config-trustpoint)#
no ocsp url
http://crlcheck.cisco.com
Removes the URL for OCSP.
Step 3
switch(config-trustpoint)#
revocation-check
oscp
Specifies OCSP as the revocation checking
method to be employed during verification of
peer certificates issued by the same CA as
that of this trust point.
Note
The OSCP URL must be configured
before specifying OSCP as a
revocation checking method.
switch(config-trustpoint)#
revocation-check crl
Specifies CRL (default) as the revocation
checking method to be employed during
verification of peer certificates issued by the
same CA as that of this trust point.
switch(config-trustpoint)#
revocation-check crl
oscp
Specifies CRL as the first revocation
checking method and OCSP as the next
method. If the CRL method fails (for
example, due to the CRL is not found or has
expired) to be used during verification of peer
certificates issued by the same CA as that of
this trust point, then OSCP is used.
Note
The OSCP URL must be configured
before specifying OSCP as a
revocation checking method.
switch(config-trustpoint)#
revocation-check
none
Does not check for revoked certificates.
switch(config-trustpoint)#
no revocation-check
Reverts to default method.
Содержание 9124 - Cisco MDS Fabric Switch
Страница 76: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 122: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 328: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 482: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 733: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m P A R T 5 Security ...
Страница 734: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 957: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m P A R T 6 IP Services ...
Страница 958: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 1182: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 1214: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 1307: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m P A R T 9 Traffic Management ...
Страница 1308: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 1331: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m P A R T 1 0 Troubleshooting ...
Страница 1332: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...