Chapter 11 Managing certificates 579

 

 

 

 

 

 

 

/cfg/cert <cert ID>

 

 

followed by:

 

 

 

 

 

display [<pass

Displays the current key and certificate, in order to save

 

phrase>]

copies as backup or for export to another device. For

 

 

more information, see “Displaying or saving a

 

 

certificate and key using the CLI” on page 591.

 

 

The display command allows you to save private

 

 

keys and certificates in the PEM format. To save a

 

 

certificate and key in another format, use the /cfg/

 

 

cert #/export command.

 

 

 

 

show

Displays detailed information about the certificate,

 

 

excluding the certificate name.

 

 

 

 

info

Displays the serial number, the expiration date, and the

 

 

values specified for the subject part of the current

 

 

certificate.

 

 

 

 

subject

Displays detailed information about the subject part of

 

 

the current certificate.

 

 

For example:

 

 

C/countryName (2.5.4.6) = US

 

 

where:

 

 

countryName is the mnemonic name

 

 

2.5.4.6 is the object identifier (OID)

 

 

US is the value

 

 

 

 

validate

Validates that the private key matches the public key in

 

 

the current certificate.

 

 

 

 

keysize

Displays the key size of the private key in the current

 

 

certificate.

 

 

 

 

keyinfo

Displays information about how the private key

 

 

associated with the currently selected certificate is

 

 

protected. For the Nortel SNAS 4050, private keys are

 

 

protected by the cluster.

 

 

 

 

del

Removes the current certificate and private key.

 

 

 

Generating and submitting a CSR using the CLI

To prepare a CSR for submission to a CA, perform the following steps:

1Access the Certificate menu by using the /cfg/cert <cert id> command, where:

Nortel Secure Network Access Switch 4050 User Guide

Page 579
Image 579
Nortel Networks 4050 manual Generating and submitting a CSR using the CLI, Phrase, Cert #/export command