Cisco PIX 525 Especificaciones Pagina 477

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 604
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 476
29-11
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 29 Configuring Certificates
Certificate Configuration
INFO: Certificate has the following attributes:
Fingerprint: 24b81433 409b3fd5 e5431699 8d490d34
Do you accept this certificate? [yes/no]: y
Trustpoint CA certificate accepted.
% Certificate successfully imported
hostname (config)#
Step 3 Generate a certificate request. To do so, use the crypto ca enroll command. The following example
shows a certificate and encryption key request for the trustpoint Main, which is configured to use manual
enrollment and general-purpose RSA keys for signing and encryption.
hostname (config)# crypto ca enroll Main
% Start certificate enrollment ..
% The fully-qualified domain name in the certificate will be:
securityappliance.example.com
% Include the device serial number in the subject name? [yes/no]: n
Display Certificate Request to terminal? [yes/no]: y
Certificate Request follows:
MIIBoDCCAQkCAQAwIzEhMB8GCSqGSIb3DQEJAhYSRmVyYWxQaXguY2lzY28uY29t
[ certificate request data omitted ]
jF4waw68eOxQxVmdgMWeQ+RbIOYmvt8g6hnBTrd0GdqjjVLt
---End - This line not part of the certificate request---
Redisplay enrollment request? [yes/no]: n
hostname (config)#
Note If you use separate RSA keys for signing and encryption, the crypto ca enroll command
displays two certificate requests, one for each key. To complete enrollment, acquire a certificate
for all certificate requests generated by the crypto ca enroll command.
Step 4 For each request generated by the crypto ca enroll command, obtain a certificate from the CA
represented by the applicable trustpoint. Be sure the certificate is in base-64 format.
Step 5 For each certificate you receive from the CA, use the crypto ca import certificate command. The
security appliance prompts you to paste the certificate to the terminal in base-64 format.
Note If you use separate RSA key pairs for signing and encryption, perform this step for each
certificate separately. The security appliance determines automatically whether the certificate is
for the signing or encryption key pair. The order in which you import the two certificates is
irrelevant.
Vista de pagina 476
1 2 ... 472 473 474 475 476 477 478 479 480 481 482 ... 603 604

Comentarios a estos manuales

Sin comentarios