HPE FlexNetwork 7500 Series Security Configuration Manual page 8

Table of Contents

Advertisement

Managing public keys ················································································· 263
Overview ························································································································································ 263
FIPS compliance ············································································································································ 263
Creating a local key pair ································································································································ 263
Distributing a local host public key ················································································································· 265
Exporting a host public key ···················································································································· 265
Displaying a host public key ··················································································································· 265
Destroying a local key pair ····························································································································· 266
Configuring a peer host public key ················································································································· 266
Importing a peer host public key from a public key file ·········································································· 266
Entering a peer host public key ·············································································································· 267
Displaying and maintaining public keys ········································································································· 267
Examples of public key management ············································································································ 267
Example for entering a peer host public key ·························································································· 267
Example for importing a public key from a public key file ······································································ 269
Configuring PKI ··························································································· 272
Overview ························································································································································ 272
PKI terminology ······································································································································ 272
PKI architecture ······································································································································ 273
PKI operation ········································································································································· 273
PKI applications ····································································································································· 274
Support for MPLS L3VPN ······················································································································ 274
FIPS compliance ············································································································································ 275
PKI configuration task list ······························································································································· 275
Configuring a PKI entity ································································································································· 275
Configuring a PKI domain ······························································································································ 276
Requesting a certificate ································································································································· 278
Configuration guidelines ························································································································· 278
Configuring automatic certificate request ······························································································· 279
Manually requesting a certificate ············································································································ 279
Aborting a certificate request ························································································································· 280
Obtaining certificates ····································································································································· 280
Configuration prerequisites ···················································································································· 280
Configuration guidelines ························································································································· 281
Configuration procedure ························································································································· 281
Verifying PKI certificates ································································································································ 281
Verifying certificates with CRL checking ································································································ 282
Verifying certificates without CRL checking ··························································································· 282
Specifying the storage path for the certificates and CRLs ············································································· 283
Exporting certificates ······································································································································ 283
Removing a certificate ··································································································································· 284
Configuring a certificate-based access control policy ···················································································· 284
Displaying and maintaining PKI ····················································································································· 285
PKI configuration examples ··························································································································· 286
Requesting a certificate from an RSA Keon CA server ·········································································· 286
Requesting a certificate from a Windows Server 2003 CA server ························································· 289
Requesting a certificate from an OpenCA server ··················································································· 292
Certificate-based access control policy configuration example ······························································ 295
Certificate import and export configuration example ·············································································· 297
Troubleshooting PKI configuration ················································································································· 302
Failed to obtain the CA certificate ·········································································································· 302
Failed to obtain local certificates ············································································································ 302
Failed to request local certificates ·········································································································· 303
Failed to obtain CRLs ····························································································································· 304
Failed to import the CA certificate ·········································································································· 305
Failed to import a local certificate ··········································································································· 305
Failed to export certificates ···················································································································· 305
Failed to set the storage path ················································································································· 306
vi

Advertisement

Table of Contents
loading

Table of Contents