7
Authentication policy for fabric elements
Importing CA for FCAP
Once you receive the files back from the Certificate Authority, you will need to install or import them
onto the local and remote switches.
1. Log in to the switch using an account with admin permissions, or an account associated with
2. Enter the secCertUtil import –fcapswcert command and verify the CA certificates are
Importing the FCAP switch certificate
ATTENTION
The CA certificates must be installed prior to installing the switch certificate.
1. Log in to the switch using an account with admin permissions, or an account associated with
2. Enter the secCertUtil import –fcapcacert command.
Starting FCAP authentication
1. Log in to the switch using an account with admin permissions, or an account with OM
2. Enter the authUtil
3. Enter the authUtil
152
Enter Login Name: jdoe
jdoe@10.1.2.3's password: <hidden text>
Success: exported FCAP CA certificate
the chassis role and having OM permissions for the PKI RBAC class of commands.
consistent on both local and remote switches.
switch:admin> seccertutil import -fcapcacert
Select protocol [ftp or scp]: scp
Enter IP address: 10.1.2.3
Enter remote directory: /myHome/jdoe/OPENSSL
Enter certificate name (must have a ".pem"
Enter Login Name: jdoe
jdoe@10.1.2.3's password: <hidden text>
Success: imported certificate [CACert.pem].
the chassis role and having OM permissions for the PKI RBAC class of commands.
switch:admin> seccertutil import -fcapswcert
Select protocol [ftp or scp]: scp
Enter IP address: 10.1.2.3
Enter remote directory: /myHome/jdoe/OPENSSL
Enter certificate name (must have ".crt" or ".cer" ".pem" or ".psk"
suffix):01.pem
Enter Login Name: jdoe
jdoe@10.1.2.3's password: <hidden text>
Success: imported certificate [01.pem].
permissions for the Authentication RBAC class of commands.
authinit command to start the authentication using the newly imported
--
certificates.
policy
--
makes the changes permanent and forces the switch to request authentication.
sw command and select active or on, the default is passive. This
-
suffix):CACert.pem
Fabric OS Administrator's Guide
53-1002446-01
Need help?
Do you have a question about the SN3000B and is the answer not in the manual?