appliance sends the certificate to the SSL peer for an SSL connection, but
the peer can reject the certificate as not valid.
Guidelines
The
password
or
password-alias
keyword is required only when a certificate file is
password-protected.
Prior to using the
password-alias
keyword, you must use the
password-map
command to 3DES-encrypt the certificate password and associate an alias with the
encrypted password. An attempt to reference an encrypted password not found in
the Password map results in command failure.
v
In environments that use plaintext (unencrypted) passwords, the
password
argument is used to open and read the certificate file.
v
In environments that use encrypted passwords, the
password-alias
argument is
searched for in the password map file and its associated encrypted password is
identified. The encrypted password, in turn, is 3DES-decrypted (using the locally
generated host key) to yield the plaintext password used to open and read the
certificate file.
Use the
certificate
command in conjunction with the
key
and
idcred
commands to
create an Identification Credentials. An Identification Credentials consists of a
certificate, which contains a public key, and the corresponding private key.
Use the
certificate
command in conjunction with the
valcred
command to create a
Validation Credentials. A Validation Credentials can be used, but is not required,
during the SSL handshake procedure to authenticate the certificate that is received
from the remote SSL peer.
The
no certificate
command deletes only the alias for the stored certificate. The file
that contains the actual certificate remains on the appliance.
Related Commands
certificate
(Crypto Validation),
copy
,
key
,
password-map
,
profile
,
valcred
Examples
v
Creates the
bob
alias for the
bob.pem
X.509 certificate. Stores the target certificate
in the public cryptographic area.
# certificate
bob pubcert:bob.pem
Creating certificate 'bob'
#
v
Creates an the
bob
alias for the
bob.pem
certificate. Stores the target certificate in
the public cryptographic area. Allows the certificate to be accessed with the
pikesville
plaintext password.
# certificate bob pubcert:bob.pem
password pikesville
Creating certificate 'bob'
#
v
Creates an the
bob
alias for the
bob.pem
certificate. Stores the target certificate in
the public cryptographic area. Allows the certificate to be accessed with the
dundaulk
encrypted password alias.
214
Command Reference
Содержание WebSphere XS40
Страница 1: ...WebSphere DataPower XML Security Gateway XS40 Command Reference Version 3 7 2 ...
Страница 2: ......
Страница 3: ...WebSphere DataPower XML Security Gateway XS40 Command Reference Version 3 7 2 ...
Страница 44: ...18 Command Reference ...
Страница 194: ...168 Command Reference ...
Страница 198: ...172 Command Reference ...
Страница 206: ...180 Command Reference ...
Страница 210: ...184 Command Reference ...
Страница 222: ...196 Command Reference ...
Страница 232: ...206 Command Reference ...
Страница 238: ...212 Command Reference ...
Страница 268: ...242 Command Reference ...
Страница 272: ...246 Command Reference ...
Страница 276: ...250 Command Reference ...
Страница 288: ...262 Command Reference ...
Страница 292: ...266 Command Reference ...
Страница 298: ...272 Command Reference ...
Страница 320: ...294 Command Reference ...
Страница 322: ...296 Command Reference ...
Страница 340: ...314 Command Reference ...
Страница 344: ...318 Command Reference ...
Страница 352: ...326 Command Reference ...
Страница 360: ...334 Command Reference ...
Страница 368: ...342 Command Reference ...
Страница 376: ...350 Command Reference ...
Страница 386: ...360 Command Reference ...
Страница 392: ...366 Command Reference ...
Страница 396: ...370 Command Reference ...
Страница 402: ...376 Command Reference ...
Страница 404: ...378 Command Reference ...
Страница 408: ...382 Command Reference ...
Страница 446: ...420 Command Reference ...
Страница 450: ...424 Command Reference ...
Страница 456: ...430 Command Reference ...
Страница 458: ... message type Extranet Message type configuration mode no message matching TFDef2 432 Command Reference ...
Страница 520: ...494 Command Reference ...
Страница 536: ...510 Command Reference ...
Страница 550: ...524 Command Reference ...
Страница 584: ...558 Command Reference ...
Страница 600: ...574 Command Reference ...
Страница 605: ... timeout 500 Chapter 63 RADIUS configuration mode 579 ...
Страница 606: ...580 Command Reference ...
Страница 638: ...v Allow access by the admin account to all access methods restrict admin off 612 Command Reference ...
Страница 650: ...624 Command Reference ...
Страница 667: ...v Specifies support for SNMP Version 2c the default state version 2c Chapter 72 SNMP Settings configuration mode 641 ...
Страница 668: ...642 Command Reference ...
Страница 704: ...678 Command Reference ...
Страница 714: ...688 Command Reference ...
Страница 726: ...700 Command Reference ...
Страница 734: ...708 Command Reference ...
Страница 752: ...726 Command Reference ...
Страница 756: ...730 Command Reference ...
Страница 804: ...778 Command Reference ...
Страница 880: ...854 Command Reference ...
Страница 892: ...866 Command Reference ...
Страница 912: ...886 Command Reference ...
Страница 918: ...892 Command Reference ...
Страница 940: ...914 Command Reference ...
Страница 946: ...920 Command Reference ...
Страница 974: ...948 Command Reference ...
Страница 1004: ...978 Command Reference ...
Страница 1030: ...1004 Command Reference ...
Страница 1032: ...1006 Command Reference ...
Страница 1038: ...Other company product and service names may be trademarks or service marks of others 1012 Command Reference ...
Страница 1065: ......
Страница 1066: ... Printed in USA ...