Connectivity Guide

Table Of Contents
Organization Name (eg, company) []:Starfleet Command
Organizational Unit Name (eg, section) []:NCC-1701A
Common Name (eg, YOUR name) [hostname]:S4148-001
Email Address []:scotty@starfleet.com
If the system is in FIPS mode (crypto fips enable command), the CSR and private key are
generated using approved algorithms from a cryptographic library that has been validated against the
FIPS 140-2 standard. You can install the FIPS-compliant certificate-key pair using the crypto cert
install command with the fips option.
Examples
OS10# crypto cert generate request cert-file home://cert1.pem key-file
home://cee OS10-VM email admin@dell.com length 1024 altname DNS.dell.com
Processing certificate ...
Successfully created CSR file /home/admin/cert1.pem and key
OS10# crypto cert generate self-signed cert-file home://cert2.pem key-
file home:e OS10-VM email admin@dell.com length 1024 altname.dell.com
validity 365
Processing certificate ...
Successfully created certificate file /home/admin/cert2.pem and key
Supported
releases
10.4.3.0 or later
crypto cert install
Installs a host certificate and private key on the switch. A host certificate may be trusted from a CA or self-signed.
Syntax
crypto cert install cert-file cert-path key-file {key-path | private}
[password passphrase] [fips]
Parameters
cert-file cert-path Enter the local path to where the downloaded certificate is stored. You
can enter a full path or a relative path; for example, home://s4048-001-cert.pem or usb://
s4048-001-cert.pem or flash://certs/s4810-001-request.crt.
key-file {key-path | private} Enter the local path to retrieve the downloaded or locally
generated private key. Specify a key-path to install the key from a local directory. Enter private to
install the key from a local hidden location. After the certificate is successfully installed, the private
key is deleted from the specified key-path location and copied to the hidden location.
password passphrase (Optional) Enter the password used to decrypt the private key if it was
generated using a password.
fips (Optional) Install the certificate-key pair as FIPS-compliant. Enter fips to install a
certificate-key pair that a FIPS-aware application, such as RADIUS over TLS, uses. If you do not
enter fips, the certificate-key pair is stored as a non-FIPS compliant pair.
Default Not configured
Command mode EXEC
Usage
information
Before using the crypto cert install command, copy a CA-signed certificate to the home
directory on the switch using a secure connection, such as HTTPS, SCP, or SFTP, and (optionally) the
private key. To delete a trusted certificate, use the crypto cert delete command.
A successful installation of a trusted certificate requires that:
The downloaded certificate is correctly formatted.
The downloaded certificates public key corresponds to the private key.
You can assign an installed certificate-key pair to a security profile by entering the file name of the
certificate without an extension.
804 Security