P-662H/HW-D Series User’s Guide

APPENDIX I

Certificates Commands

The following describes the certificate commands. See Appendix H on page 419 for information on the command structure.

All of these commands start with certificates.

Table 166

Certificates Commands

 

 

 

 

 

 

COMMAND

 

DESCRIPTION

 

 

 

 

 

 

 

my_cert

 

 

 

 

 

 

create

 

 

 

 

create

selfsigned

Create a self-signed local host certificate.

 

 

 

<name>

<name> specifies a descriptive name for the

 

 

 

<subject>

generated certificate. <subject> specifies a

 

 

 

[key size]

subject name (required) and alternative name

 

 

 

(required). The format is "subject-name-

 

 

 

 

 

 

 

 

dn;{ip,dns,email}=value". If the name contains

 

 

 

 

spaces, please put it in quotes. [key size]

 

 

 

 

specifies the key size. It has to be an integer

 

 

 

 

from 512 to 2048. The default is 1024 bits.

 

 

create

request

Create a certificate request and save it to the

 

 

 

<name>

router for later manual enrollment. <name>

 

 

 

<subject>

specifies a descriptive name for the generated

 

 

 

[key size]

certification request. <subject> specifies a

 

 

 

subject name (required) and alternative name

 

 

 

 

 

 

 

 

(required). The format is "subject-name-

 

 

 

 

dn;{ip,dns,email}=value". If the name contains

 

 

 

 

spaces, please put it in quotes. [key size]

 

 

 

 

specifies the key size. It has to be an integer

 

 

 

 

from 512 to 2048. The default is 1024 bits.

 

 

create

scep_enroll

Create a certificate request and enroll for a

 

 

 

<name> <CA

certificate immediately online using SCEP

 

 

 

addr> <CA

protocol. <name> specifies a descriptive name

 

 

 

cert> <auth

for the enrolled certificate. <CA addr> specifies

 

 

 

the CA server address. <CA cert> specifies the

 

 

 

key>

 

 

 

name of the CA certificate. <auth key> specifies

 

 

 

<subject>

the key used for user authentication. If the key

 

 

 

[key size]

contains spaces, please put it in quotes. To

 

 

 

 

leave it blank, type "". <subject> specifies a

 

 

 

 

subject name (required) and alternative name

 

 

 

 

(required). The format is "subject-name-

 

 

 

 

dn;{ip,dns,email}=value". If the name contains

 

 

 

 

spaces, please put it in quotes. [key size]

 

 

 

 

specifies the key size. It has to be an integer

 

 

 

 

from 512 to 2048. The default is 1024 bits.

Appendix I Certificates Commands

421