Configuring Secure Socket Layer (SSL)
Configuring the Switch for SSL Operation
To Generate or Erase the Switch’s Server Certificate
with the CLI
Because the host certificate is stored in flash instead of the running-config
file, it is not necessary to use
write memory
to save the certificate. Erasing the
host certificate automatically disables SSL.
CLI commands used to generate a Server Host Certificate.
Syntax:
crypto key generate cert [rsa] < 512 | 768 |1024 >
Generates a key pair for use in the certificate.
crypto key zeroize cert
Erases the switch’s certificate key and disables SSL opera
tion.
crypto host-cert generate self-signed [arg-list]
Generates a self signed host certificate for the switch. If a
switch certificate already exists, replaces it with a new
certificate. (See the Note, above.)
crypto host-cert zeroize
Erases the switch’s host certificate and disables SSL opera
tion.
To generate a host certificate from the CLI:
i.
Generate a certificate key pair. This is done with the
crypto key
generate cert
command. The default key size is 512.
N o t e :
If a certificate key pair is already present in the switch, it is not necessary to
generate a new key pair when generating a new certificate. The existing key
pair may be re-used and the crypto key generate cert command does not have
to be executed
ii. Generate a new self-signed host certificate. This is done with the
crypto host-cert generate self-signed [
Arg-List]
command.
N o t e :
When generating a self-signed host certificate on the CLI if there is not
certificate key generated this command will fail.
8-10
Содержание J8697A
Страница 1: ...6200yl Access Security Guide 5400zl 3500yl ProCurve Switches K 11 XX www procurve com ...
Страница 2: ......
Страница 22: ...Product Documentation Feature Index xx ...
Страница 55: ...Configuring Username and Password Security Front Panel Security 2 21 ...
Страница 56: ...Configuring Username and Password Security Front Panel Security 2 22 ...
Страница 58: ...Virus Throttling Contents Operating Notes 3 30 Connection Rate Log and Trap Messages 3 31 3 2 ...
Страница 88: ...Virus Throttling Connection Rate Log and Trap Messages This page is intentionally unused 3 32 ...
Страница 118: ...Web and MAC Authentication Client Status This page intentionally unused 4 30 ...
Страница 230: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup This page is intentionally unused 8 22 ...
Страница 356: ...Configuring and Monitoring Port Security Operating Notes for Port Security 11 44 ...
Страница 370: ...Using Authorized IP Managers Operating Notes This page is intentionally unused 12 14 ...
Страница 388: ...10 Index ...
Страница 389: ......