Nortel 3050 Command Reference Manual page 153

Vpn gateway
Hide thumbs Also See for 3050:
Table of Contents

Advertisement

Table 44
Certificate Menu Options (/cfg/cert) (cont'd.)
Command Syntax and Usage
sign <pasted contents of CSR file>
test <country code> <state or province> <locality>
<organization> <organizational unit> <common name> <e-mail
address> <subject alternative name> <validity period> <key
size>
Copyright © 2007 Nortel Networks
.
/cfg/cert <id> Certificate Management Configuration 153
Generates a certificate signing request (CSR), which can be further
processed by a certificate authority (CA) such as VeriSign, Entrust,
or any other CA. During the process of generating a CSR, you are
asked whether to generate a new private key. The default answer is
Yes. However, if you want to generate a CSR using the existing private
key, you should answer No. If your existing certificate is reaching its
expiration date and you only want to renew it, you should keep using
the existing private key and answer No.
For more information about how to generate a CSR, see the
"Generating and Submitting a CSR Using the CLI" section in the
"Certificates and Client Authentication" chapter in the User's Guide.
Note: When generating the certificate signing request, all questions
need not be answered. Only one of Common Name and E-mail is strictly
required.
Signs a CSR (Certificate Signing Request) by using the private
key associated with the currently selected certificate. First, open
the CSR file in a text editor and copy the entire contents, including
the text "-----BEGIN CERTIFICATE REQUEST-----" and "-----END
CERTIFICATE REQUEST-----". Then, after having issued the sign
command, follow the instructions on screen.
Note: This command is primarily intended to be used when you
have configured the virtual SSL server to perform end to end
encryption, and you want to sign a CSR generated on a backend
web server by using a CA certificate on the VPN Gateway. (The
signed CSR can then be installed on the backend web server as a
server certificate). In such a configuration, make sure the certificate
you used for signing the CSR is specified as a CA certificate on the
virtual SSL server. To set a certificate as a CA certificate used by a
particular virtual SSL server, enter the command /cfg/ssl/server
#/adv/sslconnect/verify/cacerts and specify the index number
of the appropriate CA certificate.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

3070Nvg 3050Nvg 3070Svm 10001000 con?guration guide

Table of Contents