Crypto Pki Enroll User - Allied Telesis x510-28GTX Command Reference Manual

Stackable gigabit edge switches x510 series
Table of Contents

Advertisement

P
K
I
C
UBLIC
EY
NFRASTRUCTURE
OMMANDS

CRYPTO PKI ENROLL USER

crypto pki enroll user
Overview
Use this command to enroll a single RADIUS user or all RADIUS users to the
specified trustpoint.
Use the no variant of this command to remove the PKCS#12 file from the system.
Note that the PKCS#12 files are generated in a temporary (volatile) file system, so a
system restart also results in removal of all of the files.
crypto pki enroll <trustpoint> 
Syntax
{user <username>|local-radius-all-users}
no crypto pki enroll <trustpoint> 
{user <username>|local-radius-all-users}
Mode
Privileged Exec
Usage
For RADIUS users, "enrollment" is the process of generating a private key and a
corresponding client certificate for each user, with the certificate signed by the
root CA for the trustpoint. The resulting certificates may be exported to client
devices, for use with PEAP or EAP-TLS authentication with the local RADIUS server.
The specified trustpoint must represent a locally self-signed certificate authority.
The private key and certificate are packaged into a PKCS#12-formatted file,
suitable for export using the crypto pki export pkcs12 command. The private key
is encrypted for security, with a passphrase that is entered at the command line.
The passphrase is required when the PKCS#12 file is imported on the client system.
The passphrase is not stored anywhere on the device, so users are responsible for
remembering it until the export-import process is complete.
If local-radius-all-users is specified instead of an individual user, then keys and
certificates for all RADIUS users will be generated at once. All the keys will be
encrypted using the same passphrase.
The specified trustpoint must already exist, it must represent a locally self-signed
CA, and it must already have been authenticated.
Example
To enroll the user "example-user" with the trustpoint "example", use the following
commands:
awplus>
awplus#
C613-50170-01 Rev B
Parameter
Description
<trustpoint>
The name of the trustpoint to which users are to be enrolled.
<username>
The name of the user to enroll to the trustpoint.
enable
crypto pki enroll example user example-user
Command Reference for x510 Series
AlliedWare Plus™ Operating System - Version 5.4.7-1.x
1955

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents