Tavve zoneranger User Manual page 299

Table of Contents

Advertisement

2. Install by key and SSL certificate
3. Install by keystore
4. Revert to original SSL certificate
5. Display usage
Option 1: Install by PKCS #12
configSSL [ -pkcs12 pkcs_file [ -password password ] ]
pkcs_file
Password
This option is used to load a new SSL certificate on the Ranger Gateway using a PKCS #12 file
as the source of the security information.
Option 2: Install by key and SSL Certificate
configSSL [ -certificate cert_file [ -pem pem_file ] [ -pemPassword
cert_file specifies the file containing an signed SSL certificate.
pem_file specifies the file containing the private key in X.509 format.
password specifies the password needed to access the private key.
This option is used to load a new SSL certificate on the Ranger Gateway using a X.509 file as
the source of the security information.
Option 3: Install by keystore
configSSL [ -keystore key_file [ -keystorePassword kp_password ]
key_file
kp_password specifies the password to access the keystore file.
ke_password specifies the password needed to access the private key.
This option is used to load a new SSL certificate on the Ranger Gateway using a Java Keystore
as the source of the security information.
Option 4: Revert to original SSL certificate
This option reverts the presently used SSL certificate back to the Tavve original SSL certificate.
After a certificate is installed on the Ranger Gateway, you must use the ZoneRanger web
interface to configure joined ZoneRangers to accept connections using the new certificate. If
not already present, the Trusted Subject which is associated with the new SSL Certificate must
be added on the Configuration > Ranger Gateway page SSL Trust tab on the ZoneRanger.
configTacacsServers
configTacacsServers [ -list ] | [ -remove tacacsServer [ port ]] | [
-list
-
remove
ZoneRanger 5.5 User's Guide
specifies the file containing an SSL certificate in PCKS #12 format.
specifies the password needed to access the SSL certificate.
password ] ]
[ -keyEntryPassword ke_password ] ]
specifies the file in keystore format containing the SSL keys and certificates
-spoof on|off] | [ -log none | short | full]
displays the list of TACACS+ servers needed prior to Ranger Gateway 5.0
can be used to remove the specified TACACS+ servers from the list
299

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents