Keys - Cisco 11503 - CSS Content Services Switch Configuration Manual

Content services switch ssl configuration guide
Hide thumbs Also See for 11503 - CSS Content Services Switch:
Table of Contents

Advertisement

Chapter 3
Configuring SSL Certificates and Keys
Caution
Configuring the Default SFTP or FTP Server to Import Certificates
and Private Keys
Note
OL-5655-01
For details about configuring Secure Shell Daemon on the CSS, refer to
Note
the Cisco Content Services Switch Security Configuration Guide.
On the SFTP server, verify that the server is properly configured so that the
user directory points to the directory where the certificates and keys reside.
This path is required to ensure certificates and keys are properly copied from
or to the SFTP server.
When using SSH, ensure that the CSS is not configured to perform a network boot
from a network-mounted file system on a remote system (a diskless environment).
If SSH is enabled and the CSS has been booted using a network boot from a
network-mounted file system, the CSS logs an error message by SSH as the
protocol attempts to initialize and then exits from operation, which impacts
importing and exporting certificates and keys.
Before you begin, use the ftp-record command to define the SFTP or FTP server
that you intend to use to download imported certificates and private keys to the
CSS disk. For details about using the ftp-record command to create an SFTP or
FTP record file to use when accessing the server from the CSS, refer to the Cisco
Content Services Switch Administration Guide.
When defining the FTP record for the copy ssl command, ensure that the base
directory, if used, is relative to the SSH directory where the SSH server resides.
For example, if the username is sshlogin and the SSH server is installed in
d:\Program Files\Network, the default directory for the files would
be d:\Program Files\Network\ssh. This path is required to ensure certificates and
keys are properly copied to or from the SFTP server.
For example, to define the ssl_record, enter:
# ftp-record ssl_record 192.168.19.21 johndoe "abc123" /home/johndoe
Importing or Exporting Certificates and Private Keys
Cisco Content Services Switch SSL Configuration Guide
3-13

Advertisement

Table of Contents
loading

This manual is also suitable for:

11500 series

Table of Contents