Example Configurations; Configuring Certificates On The Mds Switch - Cisco AP775A - Nexus Converged Network Switch 5010 Configuration Manual

Fabric manager configuration guide, release 4.x
Hide thumbs Also See for AP775A - Nexus Converged Network Switch 5010:
Table of Contents

Advertisement

Chapter 43
Configuring Certificate Authorities and Digital Certificates
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
Click Yes or No in the Confirmation dialog box.
Step 4
Note

Example Configurations

This section shows an example of the tasks you can use to configure certificates and CRLs on the Cisco
MDS 9000 Family switches using the Microsoft Windows Certificate server.
This section includes the following topics:

Configuring Certificates on the MDS Switch

To configure certificates on an MDS switch using Fabric Manager, follow these steps:
Choose Switches and set the LogicalName field to configure the switch host name.
Step 1
Choose Switches > Interfaces > Management > DNS and set the DefaultDomainName field to
Step 2
configure.
Step 3
To create an RSA key-pair for the switch, follow these steps:
a.
b.
c.
To create a trust point and associate the RSA key-pairs with it, follow these steps:
Step 4
a.
b.
c.
d.
e.
Choose Switches > Copy Configuration and click Apply Changes to copy the running to startup
Step 5
configuration and save the trustpoint and key pair.
OL-17256-03, Cisco MDS NX-OS Release 4.x
After you delete RSA key-pairs from a switch, ask the CA administrator to revoke your switch's
certificates at the CA. You must supply the challenge password you created when you originally
requested the certificates. See
Configuring Certificates on the MDS Switch, page 43-17
Downloading a CA Certificate, page 43-19
Requesting an Identity Certificate, page 43-24
Revoking a Certificate, page 43-30
Generating and Publishing the CRL, page 43-33
Downloading the CRL, page 43-34
Importingthe CRL, page 43-36
Choose Switches > Security > PKI and select the RSA Key-Pair tab.
Click Create Row and set the name and size field.
Check the Exportable check box and click Create.
Choose Switches > Security > PKI and select the Trustpoints tab.
Click Create Row and set the TrustPointName field.
Select the RSA key-pairs from the KeyPairName drop-down menu.
Select the certificates revocation method from the CARevoke drop-down menu.
Click Create.
"Generating Certificate Requests" section on page
Cisco MDS 9000 Family Fabric Manager Configuration Guide
Example Configurations
43-12.
43-17

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents