Chapter 11 Managing certificates 575

The recommended steps to update an existing certificate are:

1Check the certificate numbers currently in use to identify an unused certificate number.

In the CLI, use the /cfg/cur cert command. In the SREM, use the Certificates > Certificates screen to add a new certificate.

2Create a new certificate, using an unused certificate number (see “Generating and submitting a CSR using the CLI” on page 579 or “Generating and submitting a CSR using the SREM” on page 601).

a Generate a CSR.

b Submit the CSR to a CA.

3When you receive the new, signed certificate, add it to the Nortel SNAS 4050 (see “Installing certificates and keys” on page 573).

4Map the new certificate to the portal server (see “Configuring SSL settings using the CLI” on page 139 or “Configuring SSL settings using the SREM” on page 176).

5After testing to verify that the new certificate works as intended, delete the old certificate.

In the CLI, use the /cfg/cert <old cert ID>/del command. In the SREM, use the Certificates > Certificates screen to remove the old certificate.

Managing private keys and certificates using the CLI

You can perform the following certificate management tasks in the CLI:

view, validate, and manage certificates and private keys (see “Managing and viewing certificates and keys using the CLI” on page 577)

generate requests for signed certificates (see “Generating and submitting a CSR using the CLI” on page 579)

add certificates by copy-and-paste (see “Adding a certificate to the Nortel SNAS 4050 using the CLI” on page 584)

add private keys by copy-and-paste (see “Adding a private key to the Nortel SNAS 4050 using the CLI” on page 587)

Nortel Secure Network Access Switch 4050 User Guide

Page 575
Image 575
Nortel Networks 4050 manual Managing private keys and certificates using the CLI