Chapter 11 Managing certificates 581

 

 

 

 

Table 121 CSR information

 

 

 

 

 

Prompt

Description

 

 

 

 

Subject alternative name (blank

Specifies alternative information for the subject if you

 

or comma separated list of

did not provide a Common Name or e-mail address.

 

URI:<uri>, DNS:<fqdn>,

The required information is a comma-separated list as

 

IP:<ip-address>,

follows:

 

email:<email-address>):

URI:<uri>, a Uniform Resource Identifier

 

 

 

 

DNS:<fqdn>, the fully qualified domain name

 

 

IP:<ip-address>

 

 

email:<email-address>

 

 

 

 

Generate new key pair (y/n) [y]:

Specifies whether you want to generate a new pair of

 

 

private and public keys. The default is y (yes).

 

 

If you are creating a CSR for a new certificate, accept

 

 

the option to generate a new key pair.

 

 

If a configured certificate is approaching its expiration

 

 

date and you want to renew it without replacing the

 

 

existing key, specify n (no). The CSR will be based on

 

 

the existing key for the specified certificate number.

 

 

 

 

Key size [1024]:

The length of the generated key, in bits. The default

 

 

value is 1024.

 

 

 

 

Request a CA certificate (y/n)

Specifies whether to request a CA certificate to use for

 

[n]:

client authentication. Request a CA certificate if you

 

 

plan to issue your own server certificates or client

 

 

certificates, generating them from the requested CA

 

 

certificate. The default is n (no).

 

 

 

 

Specify challenge password

Specifies a password to be used during manual

 

(y/n) [n]:

revocation of the certificate.

 

 

 

3Generate the CSR.

After you have provided the required information, press Enter. The CSR is generated and displayed on the screen.

4Apply the changes.

The private key is created and stored in encrypted form on the Nortel SNAS 4050 using the specified certificate number.

Nortel Secure Network Access Switch 4050 User Guide

Page 581
Image 581
Nortel Networks 4050 manual IPip-address, Emailemail-address