beautypg.com

Brocade Mobility RFS Controller CLI Reference Guide (Supporting software release 5.5.0.0 and later) User Manual

Page 55

background image

Brocade Mobility RFS Controller CLI Reference Guide

37

53-1003098-01

2

crypto pki generate self-signed

[generate-rsa-key|use-rsa-key]

subject-name

{(email ,fqdn

,ip-address ,on )}

crypto pki import [certificate|crl]

{background {on }|on }

pki

Enables PKI management. Use this command to authenticate, export, generate, or delete a trustpoint and
its associated CA certificates.

generate self-signed

Generates a self-signed CA certificate and a trustpoint

– Specify a name for the certificate and its trustpoint.

[generate-rsa-key|
use-rsa-key]

Generates a new RSA Keypair, or uses an existing RSA Keypair

generate-rsa-key – Generates a new RSA Keypair for digital authentication

use-rsa-key – Uses an existing RSA Keypair for digital authentication

– If generating a new RSA Keypair, specify a name for it. If using an existing

RSA Keypair, specify its name.

subject-name

Specify a subject name to identify the certificate.

– Specify the common name used with the CA certificate. The name should
enable you to identify the certificate easily.

Sets the deployment country code (2 character ISO code)

Sets the state name (2 to 64 characters in length)

Sets the city name (2 to 64 characters in length)

Sets the organization name (2 to 64 characters in length)

Sets the organization unit (2 to 64 characters in length)

email

Optional. Exports the CSR to a specified e-mail address

– Specify the CA’s e-mail address.

fqdn

Optional. Exports the CSR to a specified FQDN

– Specify the CA’s FQDN.

ip address

Optional. Exports the CSR to a specified device or system

– Specify the CA’s IP address.

pki

Enables PKI management. Use this command to authenticate, export, generate, or delete a trustpoint and
its associated CA certificates.

import

Imports certificates, Certificate Revocation List (CRL), or a trustpoint to the selected device

[certificate|crl]

Imports a signed server certificate or CRL

certificate – Imports signed server certificate

crl – Imports CRL

– Specify the trustpoint name (should be authenticated).

Specify the signed server certificate or CRL source address in the following format:

tftp://[:port]/path/file
ftp://:@[:port]/path/file
sftp://@[:port]>/path/file
http://[:port]/path/file
cf:/path/file
usb:/path/file