Connectivity Guide

Table Of Contents
It is possible to store a certificate in either FIPS mode or non-FIPS mode on the switch, but not in both
modes, using the crypto cert install command and the optional fips option. You must ensure
that certificates installed in FIPS mode are compliant with the FIPS 140-2 standard.
Example
OS10# crypto cert install cert-file home://Dell_host1_CA1.pem key-file
home://Dell_host1_CA1.key
Processing certificate ...
Certificate and keys were successfully installed as "Dell_host1_CA1.pem"
that may be used in a security profile. CN = Dell_host1_CA1.
Supported
releases
10.4.3.0 or later
crypto security-profile
Creates an application-specific security profile.
Syntax
crypto security-profile profile-name
Parameters profile-name Enter the name of the security profile, up to 32 characters.
Default Not configured
Command mode CONFIGURATION
Usage
information
Create a security profile for a specific application on the switch, such as RADIUS over TLS. A security
profile associates a certificate and private key pair using the certificate command. The no form of
the command deletes the security profile.
Example
OS10# crypto security-profile secure-radius-profile
OS10(config-sec-profile)#
Supported
releases
10.4.3.0 or later
show crypto ca-certs
Displays all CA certificates installed on the switch.
Syntax
show crypto ca-certs [filename]
Parameters filename (Optional) Enter the text filename of a CA certificate as shown in the show crypto
ca-certs output. Enter the filename in the format filename.crt.
Default Display all installed CA certificates.
Command mode EXEC
Usage
information
To delete a CA certificate, use the crypto ca-cert delete command. Enter the filename as shown
in the show crypto ca-certs output.
Example
OS10# show crypto ca-certs
--------------------------------------
| Locally installed certificates |
--------------------------------------
Dell_interCA1.crt
Dell_rootCA1.crt
OS10# show crypto ca-certs Dell_interCA1.crt
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 4096 (0x1000)
Signature Algorithm: sha256WithRSAEncryption
Security 805