Maximum Limits; Initial Troubleshooting Checklist; Common Troubleshooting Tools In Fabric Manager - Cisco 9134 - MDS Multilayer Fabric Switch Troubleshooting Manual

Mds 9000 family
Hide thumbs Also See for 9134 - MDS Multilayer Fabric Switch:
Table of Contents

Advertisement

Chapter 24
Troubleshooting Digital Certificates
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
4.
5.
6.
Cisco MDS SAN-OS supports certificate retrieval and enrollment using a manual cut-and-paste method.
Cut-and-paste enrollment literally means you must cut and paste the certificate requests and resulting
certificates between the switch (using a console, Telnet, or SSH connection) and the CA, as follows:
1.
2.
3.
4.

Maximum Limits

Table 24-1
Table 24-1
Feature
Trust points declared on a switch
RSA key pairs generated on a switch
Identity certificates configured on a switch
Certificates in a CA certificate chain
Trust points authenticated to a specific CA

Initial Troubleshooting Checklist

Begin troubleshooting digital certificates issues by checking the following issues first:
Checklist
Verify that the fully qualified domain name (FQDN) has been configured on the switch.
Verify that all the CA certificates in a CA chain for a trusted CA are added to the switch if
the CA is not self-signed.
Verify that you have installed your identity certificates.
Verify that you have revoked your identity certificates if you delete the associated RSA key
pairs.

Common Troubleshooting Tools in Fabric Manager

Choose Switches > Security > PKI to access digital certificates.
OL-9285-05
Might require manual intervention at the CA server by the CA administrator to approve the
enrollment request when it is received by the CA.
Receive the issued certificate back from the CA, signed with the CA's private key.
Write the certificate into a nonvolatile storage area on the switch (bootflash).
Create an enrollment certificate request, which is displayed in base64-encoded text form.
Cut and paste the encoded certificate request text in an e-mail message or in a web form and send it
to the CA.
Receive the issued certificate (in base64-encoded text form) from the CA in an e-mail message or
in a web browser download.
Cut and paste the issued certificate to the switch using the certificate import facility.
lists the maximum limits for CAs and digital certificate parameters.
Maximum Limits for CA and Digital Certificate
Maximum Limit
16
16
16
10
10
Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x
Initial Troubleshooting Checklist
Check off
24-3

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents