Users Guide

Table Of Contents
2. certificate-name .pem
show crypto certs
certificate certificate-name
exit
3. SECURITY-PROFILE CRL CRL 使 CRL
revocation-check
4.
peer-name-check
5. 使 X.509v3 使 X.509v3 RADIUS over TLS
radius-server host tls
radius-server host {hostname | ip-address} tls security-profile profile-name
[auth-port port-number] key {0 authentication-key | 9 authentication-key |
authentication-key}
RADIUS over TLS
OS10# show crypto cert
--------------------------------------
| Installed non-FIPS certificates |
--------------------------------------
dv-fedgov-s6010-1.pem
--------------------------------------
| Installed FIPS certificates |
--------------------------------------
OS10#
OS10(config)#
OS10(config)# crypto security-profile radius-prof
OS10(config-sec-profile)# certificate dv-fedgov-s6010-1
OS10(config-sec-profile)# revocation-check
OS10(config-sec-profile)# peer-name-check
OS10(config-sec-profile)# exit
OS10(config)#
OS10(config)# radius-server host radius-server-2.test.com tls security-profile radius-
prof key radsec
OS10(config)# end
OS10# show running-configuration crypto security-profile
!
crypto security-profile radius-prof
certificate dv-fedgov-s6010-1
OS10# show running-configuration radius-server
radius-server host radius-server-2.test.com tls security-profile radius-prof key 9
2b9799adc767c0efe8987a694969b1384c541414ba18a44cd9b25fc00ff180e9
VLT 使 VLT
OS10 X.509v3
访 OS10
X.509v3 2021 7 27 VLT
: 10.5.0.0 OS10 2021 7 27
X.509v3
使 cluster security-profile X.509v3
VLT 使 X.509v3
CA
949