574Chapter 11 Managing certificates

If you use the certificate index number of an installed certificate when adding a new certificate, the installed certificate is overwritten.

After you have installed the certificate, map it to the Nortel SNAS 4050 portal (see “Configuring SSL settings using the CLI” on page 139 or “Configuring SSL settings using the SREM” on page 176).

Saving or exporting certificates and keys

You can extract copies of certificates and keys to save as backup or to install on another device.

There are two ways to retrieve a certificate and key from the Nortel SNAS 4050 cluster:

by copying (see “Displaying or saving a certificate and key using the CLI” on page 591 or “Displaying or saving a certificate and key using the SREM” on page 605)

by exporting to a TFTP/FTP/SCP/SFTP server (see “Exporting a certificate and key from the Nortel SNAS 4050 using the CLI” on page 594 or “Exporting a certificate and key from the Nortel SNAS 4050 using the SREM” on page 607)

The copy-and-paste method saves the certificate and key in PEM format.

The export method allows you to choose from a variety of file formats. Nortel recommends using the PKCS12 format (also known as PFX). Most web browsers accept importing a combined key and certificate file in the PKCS12 format. For more information about the formats supported on the Nortel SNAS 4050, see “Key and certificate formats” on page 571.

Updating certificates

To update or renew an existing certificate, do not replace the existing certificate by using its certificate number when you generate the CSR or add the new certificate. Rather, keep the existing certificate until you have verified that the new certificate works as designed.

320818-A

Page 574
Image 574
Nortel Networks 4050 manual Saving or exporting certificates and keys, Updating certificates