Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell EMC SmartFabric OS10 User Guide Release 10.5.0

X.509v3 certificates

OS10 supports X.509v3 certificates to secure communications between the switch and a host, such as a RADIUS server. Both the switch and the server exchange a public key in a signed X.509v3 certificate issued by a certificate authority (CA) to authenticate each other. The certificate authority uses its private key to sign the switch and host certificates.

The information in the certificate allows both devices to prove ownership and the validity of a public key. Assuming the CA is trusted, the switch and authentication server validate each other's identity and set up a secure, encrypted communications channel.

User authentication with a public key certificate is usually preferred over password-based authentication, although you can use both at the same time, to:
  • Avoid the security risk of using low-strength passwords and provide greater resistance to brute-force attacks.
  • Provide assurance of trusted, provable identities (when using certificates digitally signed by a trusted CA).
  • Provide security and confidentiality in switch-server communications in addition to user authentication.
For example, you can download and install a X.509v3 certificate to enable public-key authentication in RADIUS over TLS authentication — also called RadSec. OS10 supports a public key infrastructure (PKI), including:
  • Generation of self-signed certificates and certificate signing requests (CSRs), and their corresponding private keys
  • Installation and deletion of self-signed certificates and CA-signed certificates
  • Secure deletion of corresponding private keys
  • Installation and deletion of CA certificates in the system "trust store"
  • Display of certificate information

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\