Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell EMC SmartFabric OS10 User Guide Release 10.5.0

PDF

示例:使用 X.509v3 证书配置 RADIUS over TLS

本示例显示如何安装支持 RADIUS over TLS 身份验证的受信任 X.509v3 CA 和主机证书密钥对。

1. 安装受信任的 CA 证书。

OS10# copy tftp://CAadmin:secret@172.11.222.1/GeoTrust_Universal_CA.crt home://GeoTrust_Universal_CA.crt 
OS10# crypto ca-cert install home://GeoTrust_Universal_CA.crt
Processing certificate ...
Installed Root CA certificate
CommonName = GeoTrust Universal CA
IssuerName = GeoTrust Universal CA

2. 生成 CSR,将 CSR 复制到 CA 服务器、下载签名的证书,并安装主机证书。

OS10# crypto cert generate request cert-file home://s4048-001-csr.pem
key-file home://tsr6-key.pem cname "Top of Rack 6" altname "IP:10.0.0.6 DNS:tor6.dell.com" 
email admin@dell.com organization "Dell EMC" orgunit Networking locality "santa Clara" 
state California country US length 1024
Processing certificate ...
Successfully created CSR file /home/admin/tor6-csr.pem and key

OS10# copy home://tor6-csr.pem scp://CAadmin:secret@172.11.222.1/s4048-001-csr.pem 

OS10# copy scp://CAadmin:secret@172.11.222.1/s4048-001.crt usb://s4048-001-crt.pem 

OS10# crypto cert install crt-file usb://s4048-001-crt.pem key-file usb://s4048-001-crt.key
This will replace the already installed host certificate.
Do you want to proceed ? [yes/no(default)]:yes
Processing certificate ...
Host certificate installed successfully.

3. 配置 X.509v3 安全配置文件。

OS10# show crypto cert
--------------------------------------
|    Installed non-FIPS certificates    |
--------------------------------------
s4048-001-csr.pem
--------------------------------------
|    Installed FIPS certificates    |
--------------------------------------

OS10# config terminal
OS10(config)# crypto security-profile radius-admin
OS10(config-sec-profile)# certificate s4048-001-csr
OS10(config-sec-profile)# exit

4. 配置 RADIUS over TLS 服务器。

OS10# radius-server host 10.0.0.1 tls security-profile radius-admin key radsec

5. 配置基于 RADIUS 的用户身份验证。

OS10# aaa authentication login default group radius local

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\