Fingerprint (Trustpoint Configuration Mode) - Allied Telesis x310-26FT Command Reference Manual

X310 series stackable access switches for alliedware plus version 5.4.6-1.x
Table of Contents

Advertisement

P
K
I
C
UBLIC
EY
NFRASTRUCTURE
OMMANDS
(
FINGERPRINT
TRUSTPOINT CONFIGURATION MODE

fingerprint (trustpoint configuration mode)

Overview
Use this command to declare that certificates with the specified fingerprint should
be automatically accepted, when importing certificates from an external certificate
authority. This can affect the behavior of the crypto pki authenticate and crypto
pki import pem commands.
Use the no variant of this command to remove the specified fingerprint from the
pre-accepted list.
fingerprint <word>
Syntax
no fingerprint <word>
Default
By default, no fingerprints are pre-accepted for the trustpoint.
Mode
Trustpoint Configuration
Usage
Specifying a fingerprint adds it to a list of pre-accepted fingerprints for the
trustpoint. When a certificate is imported, if it matches any of the pre-accepted
values, then it will be saved in the system automatically. If the imported
certificate's fingerprint does not match any pre-accepted value, then the user will
be prompted to verify the certificate contents and fingerprint visually.
This command is useful when certificates from an external certificate authority are
being transmitted over an insecure channel. If the certificate fingerprint is
delivered via a separate messaging channel, then pre-entering the fingerprint
value via cut-and-paste may be less errorprone than attempting to verify the
fingerprint value visually.
The fingerprint is a series of 40 hexadecimal characters. It may be entered as a
continuous string, or as a series of up to multiple strings separated by spaces. The
input format is flexible because different certificate authorities may provide the
fingerprint string in different formats.
Example
To configure a fingerprint "5A81D34C 759CC4DA CFCA9F65 0303AD83 410B03AF"
for the trustpoint named "example", use the following commands:
awplus>
awplus#
awplus(config)#
awplus(ca-trustpoint)#
0303AD83 410B03AF
Related
crypto pki authenticate
Commands
C613-50103-01 REV A
)
Parameter
Description
<word>
The fingerprint as a series of 40 hexadecimal characters,
optionally separated into multiple character strings.
enable
configure terminal
crypto pki trustpoint example
Command Reference for x310 Series
AlliedWare Plus™ Operating System - Version 5.4.6-1.x
fingerprint 5A81D34C 759CC4DA CFCA9F65
1829

Advertisement

Table of Contents
loading

This manual is also suitable for:

X310-26fpX310-50fpX310-50ft

Table of Contents