Cisco MDS 9000 Series Configuration Manual page 135

Security
Hide thumbs Also See for MDS 9000 Series:
Table of Contents

Advertisement

Configuring Certificate Authorities and Digital
Certificates
This chapter includes the following sections:
About CAs and Digital Certificates
Public Key Infrastructure (PKI) support provides the means for the Cisco MDS 9000 Family switches to
obtain and use digital certificates for secure communication in the network. PKI support provides manageability
and scalability for IPsec/IKE and SSH.
CAs manage certificate requests and issue certificates to participating entities such as hosts, network devices,
or users. The CAs provide centralized key management for the participating entities.
Digital signatures, based on public key cryptography, digitally authenticate devices and individual users. In
public key cryptography, such as the RSA encryption system, each device or user has a key-pair containing
both a private key and a public key. The private key is kept secret and is known only to the owning device or
user only. However, the public key is known to everybody. The keys act as complements. Anything encrypted
with one of the keys can be decrypted with the other. A signature is formed when data is encrypted with a
sender's private key. The receiver verifies the signature by decrypting the message with the sender's public
key. This process relies on the receiver having a copy of the sender's public key and knowing with a high
degree of certainty that it really does belong to the sender and not to someone pretending to be the sender.
This section provides information about certificate authorities (CAs) and digital certificates, and includes the
following topics:
Purpose of CAs and Digital Certificates
CAs manage certificate requests and issue certificates to participating entities such as hosts, network devices,
or users. The CAs provide centralized key management for the participating entities.
About CAs and Digital Certificates, on page 117
Configuring CAs and Digital Certificates, on page 121
Example Configurations, on page 131
Maximum Limits, on page 153
Default Settings, on page 154
C H A P T E R
Cisco MDS 9000 Series Security Configuration Guide, Release 8.x
7
117

Advertisement

Table of Contents
loading

Table of Contents