HP Client Bridge M111 manual Certificate and private key store, END Certificate

Page 71

 

 

Working with the M111

 

 

Managing certificates

 

 

 

Content and

 

 

file format

Items carried in the file

Description

 

 

 

X.509 certificate in

One or more X.509 certificate

Popular format in the Unix

PEM file

 

world. X.509 DER certificate is

 

 

base64 encoded and placed

 

 

between

 

 

"-----BEGIN CERTIFICATE-----"

 

 

and

 

 

"-----END CERTIFICATE-----"

 

 

lines. Multiple certificates can be

 

 

repeated in the same file.

 

 

 

ASN.1 DER encoded

One X.509 CRL

Most basic format supported for

X.509 CRL

 

CRL.

 

 

 

X.509 CRL in PEM file

One X.509 CRL

Same format as X.509 certificate

 

 

in PEM format, except that the

 

 

lines contain BEGIN CRL and

 

 

END CRL.

 

 

 

Certificate and private key store

This list displays all certificates installed on the M111. The M111 uses these certificates and private keys to authenticate itself to peers.

The following information is displayed for each certificate in the list:

ID: A sequentially assigned number to help identify certificates with the same common name.

Issued to: Name of the certificate holder. Select the name to view the contents of the certificate.

Issued by: Name of the CA that issued the certificate.

Current usage: Lists the services that are currently using this certificate.

Delete: Select to remove the certificate from the certificate store.

Installing a new private key/public key certificate chain pair

The certificate you install must:

Be in PKCS #12 format.

Contain a private key (a password controls access to the private key).

Not have a name that is an IP address. The name should be a domain name containing at least one dot. If you try to add a certificate with an invalid name, the default certificate is restored.

The name in the certificate is automatically assigned as the domain name of the M111.

3-41

Image 71
Contents ProCurve 5400zl Switches HP ProCurve M111 Client Bridge Page HP ProCurve M111 Client Bridge Publication Number Contents Working with the M111 Field descriptions To assign a management address Regulatory information Resetting to factory defaultsViii Introduction Conventions About this guideProducts covered Important termsExample Description Commands and program listingsIntroducing the M111 Client Bridge Key featuresServicing Safety informationProfessional Installation Required Before contacting support HP ProCurve Networking supportOnline documentation Getting started Overview Scenario 1 Connecting wired devices to a wireless networkDeploying the M111 Configure your computer Configuration procedureConnect to the M111 Select Network DNS PasswordsConfigure a station profile Connect the wired computers to the M111  The printer is configured with a static IP address Configure MAC cloning options Connect the wired device to the M111 Scenario 3 Connecting a serial device to a wireless network Configure the serial connection Getting started Getting started Working with the M111 802.1X certificates Certificate stores Certificate usage Starting the management tool About passwordsManagement tool Manager and Operator accounts Customizing management tool settingsPasswords Security Security policiesAuto-refresh IP address configurationWeb server To configure IP addressing Wireless range Radio configurationRestrict channels to To configure the radioWireless mode Fast roaming threshold Fast roaming delta threshold Antenna selectionMinimum SNR threshold Scan channel delayFast scan channel delay Fast roaming threshold countRTS threshold Using station profiles to establish a wireless linkAdvanced wireless settings Transmit power controlWorking with the M111 General To add or edit a station profileEAP method Wireless securityWireless protection Key sourceWorking with the M111 Ap1certificate or ap2certificate Quality of serviceViewing APs in the neighborhood Encryption typeField descriptions Configuring Quality of Service QoSAccess category 802.1p QoS settings in a station profilePriority mechanisms Very-high, high, normal, low priority Differentiated Services DiffServUpstream DiffServ tagging DisabledCreating IP QoS profiles To define an IP QoS profileProtocol Start port/ End port Connecting serial devicesSettings Profile nameTo connect a serial device Serial port connectorRemote IP address Transmit timeoutIdle timeout ModeStop bits Drop wireless link when port 1 is connectedData bits Parity bitRx kbytes DNS configurationConnection time Tx kbytesServer DNS switch on server failureDynamically assigned DNS servers Override dynamically assigned DNS serversTo forward unsupported traffic DNS switch overEnable the Redirect unsupported traffic to option Handling unsupported trafficLimitations Cloning the address of a wired deviceIP forwarding Enabling Ethernet MAC cloning Wireless access to the M111 when MAC cloning is activeSelect Management Snmp Setting up management traffic interceptionManagement tool TCP port Snmp agent UDP portRemote log UDP port Using filters to restrict wireless trafficEnable the Wireless traffic filters option Snmp notifications UDP portTo assign a management address Assigning a management addressSnmp V3 users AttributesV1/v2c communities Notification receivers Managing certificates 802.1X certificates 802.1X Install TLS client certificate Password Install802.1X Manage CA certificates Certificate stores802.1X Manage TLS client certificates 802.1X Trusted CA certificatesCA certificate import formats Installing a new CA certificateTrusted CA certificate store END Certificate Certificate and private key storeCertificate usage Default installed private key/public key certificate chainsSpecify the Pkcs #12 password About certificate warnings Changing the certificate assigned to a serviceBackup configuration Configuration file managementManual configuration file management Scheduled operations Reset configurationRestore configuration Software updates Enable Scheduled install Performing an immediate software updatePerforming a scheduled update Select InstallWorking with the M111 Regulatory information Manufacturers FCC Declaration of Conformity Statement Countries of Operation & Conditions of Use GHz Operation Operation Using 5 GHz Channels in the European CommunityAntenna Band GHz Supported External Antennas5470 Indoor or outdoor use 1000 124, 128, 132, 136DGT LPD Low Power Device Statement Resetting to factory defaults How it works Using the Reset buttonUsing the management tool Page Technology for better business outcomes