
5-44
Configuring the RADIUS Server—Without Identity Driven Manager
Manage Digital Certificates for RADIUS
N o t e
Be very careful to enter the output file for the certificate exactly as shown
above:
/etc/raddb/certs/demoCA/cacert.pem
.
Otherwise, you must alter the name specified for the private key file and
the certificate file in the “tls” section of the
/etc/raddb/eap.conf
file—which
can lead to errors. (See step 12 on page 5-50.)
d.
When prompted, enter the NAC 800’s root password.
3.
Log in as root to the NAC 800 OS.
4.
If the CA certificate is not in PEM format, follow these steps:
a.
Move to the correct directory:
ProCurve NAC 800:/# cd /etc/raddb/certs/demoCA
b.
Convert from DER format with this command:
For example, enter:
ProCurve NAC 800:/etc/raddb/certs/demoCA# openssl
x509 -in cacert.der -inform DER -out cacert.pem
-outform PEM
Convert from PFX format with this command:
5.
Restart the RADIUS server.
ProCurve NAC 800:/etc/raddb/certs/demoCA# service
radiusd restart
Syntax:
openssl x509 -in <
filename
> -inform DER -out <
filename
> -outform PEM
Preferably, specify
cacert.pem
for the second filename.
Syntax:
openssl pkcs12 -in <
filename
>.pfx -out <
filename
>.pem
You should change the filename extension to reflect the
changed format. Preferably, specify
cacert.pem
for the
filename
Содержание 800
Страница 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Страница 2: ......
Страница 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Страница 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Страница 145: ...3 17 Initial Setup of the ProCurve NAC 800 System Settings Figure 3 9 Home System Configuration Management Server ...
Страница 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Страница 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Страница 328: ...5 64 Configuring the RADIUS Server Without Identity Driven Manager Manage Digital Certificates for RADIUS ...
Страница 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Страница 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Страница 380: ...A 26 Appendix A Glossary ...
Страница 394: ...B 14 Appendix B Linux Commands Service Commands ...
Страница 405: ......
Страница 406: ... Copyright 2007 2008 Hewlett Packard Development Company L P April 2008 Manual Part Number 5991 8618 ...