Specifications
Key and Certificate Configuration Scenarios
RoamAbout Mobility System Software Configuration Guide 16-13
Issuer: C=US, ST=CA, L=PLEAS, O=Enterasys, OU=SQA, CN=BOBADMIN/
emailAddress=BOBADMIN, unstructuredName=BOB
Validity:
Not Before: Oct 19 01:59:42 2004 GMT
Not After : Oct 19 01:59:42 2005 GMT
RBT-8100# show crypto certificate web
Certificate:
Version: 3
Serial Number: 999 (0x3e7)
Subject: C=US, ST=CA, L=PLEAS, O=
Enterasys, OU=SQA, CN=BOBADMIN/
emailAddress=BOBADMIN, unstructuredName=BOB
Signature Algorithm: md5WithRSAEncryption
Issuer: C=US, ST=CA, L=PLEAS, O=
Enterasys, OU=SQA, CN=BOBADMIN/
emailAddress=BOBADMIN, unstructuredName=BOB
Validity:
Not Before: Oct 19 02:02:02 2004 GMT
Not After : Oct 19 02:02:02 2005 GMT
Installing CA-Signed Certificates from PKCS #12 Object Files
ThisscenarioshowshowtousePKCS #12objectfilestoinstallpublic‐privatekeypairs,CA‐signed
certificates,andCAcertifiesforadministrativeaccess,802.1X(EAP)access,andWeb AAAaccess.
1. Settimeanddateparameters,ifnotalreadyset.(See“ConfiguringandManagingTime
Parameters”onpage 5‐20.)
2. ObtainPKCS #12object
filesfromacertificateauthority.
3. CopythePKCS #12objectfilestononvolatilestorageontheRoamAboutSwitch.Usethe
followingcommand:
copy tftp://filename local-filename
Forexample,tocopyPKCS #12filesnamed2048admn.p12,20481x.p12,and2048web.p12
fromtheTFTPserverattheaddress192.168.253.1,typethefollowingcommands:
RBT-8100# copy tftp://192.168.253.1/2048admn.p12 2048admn.p12
success: received 637 bytes in 0.253 seconds [ 2517 bytes/sec]
RBT-8100# copy tftp://192.168.253.1/20481x.p12 20481x.p12
success: received 637 bytes in 0.253 seconds [ 2517 bytes/sec]
RBT-8100# copy tftp://192.168.253.1/2048web.p12 2048web.p12
success: received 637 bytes in 0.253 seconds [ 2517 bytes/sec]
4. Entertheone‐timepasswords(OTPs)forthePKCS #12objectfiles.TheOTPprotectsthe
PKCS #12file.
Toenteraone‐timepassword,usethefollowingcommand:
crypto otp {admin | eap | web} one-time-password
Forexample:
RBT-8100# crypto otp admin SeC%#6@o%c
OTP set
RBT-8100# crypto otp eap SeC%#6@o%d
OTP set
RBT-8100# crypto otp web SeC%#6@o%e
OTP set