Users Guide

Table Of Contents
Processing certificate ...
Successfully created CSR file /home/admin/cert1.pem and key
OS10# crypto cert generate self-signed cert-file home://cert2.pem key-file
home:e OS10-VM email admin@dell.com length 1024 altname.dell.com validity 365
Processing certificate ...
Successfully created certificate file /home/admin/cert2.pem and key
Supported releases 10.4.3.0 or later
crypto cert install
Installs a host certicate and private key on the switch. A host certicate may be trusted from a CA or self-signed.
Syntax
crypto cert install cert-file cert-path key-file {key-path | private} [password
passphrase] [fips]
Parameters
cert-file cert-path — Enter the local path to where the downloaded certicate is stored. You can
enter a full path or a relative path; for example, home://s4048-001-cert.pem or usb://s4048-001-
cert.pem
or flash://certs/s4810-001-request.crt.
key-file {key-path | private} — Enter the local path to retrieve the downloaded or locally
generated private key. Specify a key-path to install the key from a local directory. Enter private to install the
key from a local hidden location. After the certicate is successfully installed, the private key is deleted from the
specied key-path location and copied to the hidden location.
password passphrase — (Optional) Enter the password used to decrypt the private key if it was
generated using a password.
fips — (Optional) Install the certicate-key pair as FIPS-compliant. Enter fips to install a certicate-key
pair that a FIPS-aware application, such as RADIUS over TLS, uses. If you do not enter fips, the certicate-
key pair is stored as a non-FIPS compliant pair.
Default Not congured
Command mode EXEC
Usage information Before using the crypto cert install command, copy a CA-signed certicate to the home directory on the
switch using a secure connection, such as HTTPS, SCP, or SFTP, and (optionally) the private key. To delete a
trusted certicate, use the crypto cert delete command.
A successful installation of a trusted certicate requires that:
The downloaded certicate is correctly formatted.
The downloaded certicate’s public key corresponds to the private key.
You can assign an installed certicate-key pair to a security prole by entering the le name of the certicate
without an extension.
It is possible to store a certicate in either FIPS mode or non-FIPS mode on the switch, but not in both modes,
using the crypto cert install command and the optional fips option. You must ensure that certicates
installed in FIPS mode are compliant with the FIPS 140-2 standard.
Example
OS10# crypto cert install cert-file home://Dell_host1_CA1.pem key-file home://
Dell_host1_CA1.key
Processing certificate ...
Certificate and keys were successfully installed as "Dell_host1_CA1.pem" that
may be used in a security profile. CN = Dell_host1_CA1.
992 Security