Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell EMC SmartFabric OS10 User Guide Release 10.5.2

PDF

Manage CA certificates

OS10 supports the download and installation of public X.509v3 certificates from external certificate authorities.

In a data center environment, trusted CA servers can create CA certificates. A host operates as a trusted CA server. Network hosts install certificates that are digitally signed with the CA's private key to establish trust between participating devices in the network. The certificate on an OS10 switch is used to verify the certificates presented by clients and servers, such as Syslog and RADIUS servers, to establish a secure connection with these devices.

To import a CA server certificate:
  1. Use the copy command to download an X.509v3 certificate created by a CA server using a secure method, such as HTTPS, SCP, or SFTP. Copy the CA certificate to the local directory on the switch, such as home:// or usb://.
  2. Use the crypto ca-cert install command to install the certificate. When you install a CA certificate, specify the local path where the certificate is stored.

The switch verifies the certificate and installs it in an existing directory of trusted certificates in PEM format.

Install CA certificate

  • Install a CA certificate in EXEC mode.
    crypto ca-cert install ca-cert-filepath [filename]
    • ca-cert-filepath specifies the local path to the downloaded certificate; for example, home://CAcert.pem or usb://CA-cert.pem.
    • filename specifies an optional filename that the certificate is stored under in the OS10 trust-store directory. Enter the filename in the filename.crt format.

Example: Download and install CA certificate

OS10# copy scp:///tftpuser@10.11.178.103:/tftpboot/certs/Dell_rootCA1.pem home://Dell_rootCA1.pem
password:

OS10# crypto ca-cert install home://Dell_rootCA1.pem
Processing certificate ...
Installed Root CA certificate
  CommonName = Dell_rootCA1
  IssuerName = Dell_rootCA1

Display CA server certificate

OS10# show crypto ca-certs
 --------------------------------------
|    Locally installed certificates    |
 --------------------------------------
Dell_rootCA1.crt
OS10# show crypto ca-certs Dell_rootCA1.crt
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            95:48:23:17:76:9d:05:e1
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C = US, ST = California, L = Santa Clara, O = Dell EMC, OU = Networking, CN = Dell_rootCA1
        Validity
            Not Before: Jul 25 18:21:50 2018 GMT
            Not After : Jul 20 18:21:50 2038 GMT
        Subject: C = US, ST = California, L = Santa Clara, O = Dell EMC, OU = Networking, CN = Dell_rootCA1
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (4096 bit)
                Modulus:
                    00:cd:9d:ca:10:6b:b1:54:81:10:92:42:9f:6a:cb:
                    49:51:9d:46:10:cb:67:08:2b:75:2a:62:40:80:a3:
                    f5:7d:58:67:f4:cc:c6:70:32:14:4c:f0:4d:cd:7e:
                    0d:5c:63:28:5e:6c:ad:9e:13:13:71:6d:9d:10:a9:
                    a1:d8:6b:bd:a3:a0:5a:11:19:87:4d:3d:08:6f:10:
                    03:df:70:89:5f:b7:56:49:32:57:9c:28:5e:43:7f:
                    ca:bc:41:c7:31:51:97:7f:73:b7:b0:c4:13:21:e6:
                    2c:4c:19:fd:35:0b:26:16:78:fc:c3:73:21:3a:06:
                    f6:ec:87:3f:9f:5e:3a:0c:23:5e:13:4c:9e:5a:70:
                    18:d4:ad:cb:cf:47:c1:c6:50:a0:49:df:a0:a6:47:
                    1e:13:19:49:9e:67:db:1c:c7:23:9e:37:3b:c7:0c:
                    cd:26:46:f6:c1:e1:93:64:29:81:9c:e9:a8:1d:29:
                    19:4c:8d:a4:a8:53:66:2b:b2:70:ff:ec:80:d4:87:
                    eb:74:e2:11:56:ed:4b:68:fc:53:2e:d4:94:f6:f5:
                    e4:77:d9:b6:e8:4a:91:b7:da:46:18:51:bf:e4:b6:
                    3e:6a:47:ab:77:f6:93:b7:d0:9a:c8:fa:ba:ae:ed:
                    6a:fd:81:54:c8:76:13:1b:57:74:d6:02:78:d7:98:
                    38:e6:c5:9b:64:03:b2:76:93:fd:8c:9f:54:c9:a3:
                    04:a9:0c:b7:e2:bb:02:50:3f:e0:08:33:32:89:55:
                    95:9b:30:6c:73:7d:be:63:f1:6c:da:4d:92:41:d0:
                    f5:d6:bf:e3:c0:da:98:ae:24:37:ed:07:63:86:a1:
                    cc:da:3b:45:d4:a9:80:e2:d6:ab:c1:ae:2a:99:32:
                    9d:ba:fe:88:38:f2:02:d1:b3:78:43:17:7e:6e:b1:
                    a2:17:85:bd:5f:4a:52:90:96:4d:bc:19:85:ed:9d:
                    49:77:bd:59:44:6c:6c:23:e5:b1:92:af:a0:10:ce:
                    68:d4:f4:07:9e:ec:ca:c5:95:a2:f4:19:bb:f7:12:
                    ce:f0:a6:39:df:1a:5b:10:91:d5:77:46:8d:55:9a:
                    8e:96:e0:70:f6:27:89:43:3d:74:99:b4:7f:4b:38:
                    71:18:01:64:bb:72:2c:26:6f:6e:e8:06:9a:77:4b:
                    07:3b:b3:8c:71:ff:61:1b:84:d4:02:46:47:e5:4d:
                    79:be:22:e9:7a:8c:eb:06:38:38:a6:f7:b7:83:bf:
                    f2:64:c9:b8:d9:7f:d1:cc:87:ac:80:b0:d0:d3:17:
                    35:d1:49:44:2e:6e:9f:60:9c:ca:9a:6d:cd:63:79:
                    7c:6d:33:72:13:74:f1:16:20:50:46:20:e7:c1:ff:
                    b0:42:95
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Subject Key Identifier:
                75:22:3F:BE:99:B7:FA:A1:5B:1D:68:0B:E9:5E:21:7D:83:62:AC:DB
            X509v3 Authority Key Identifier:
                keyid:75:22:3F:BE:99:B7:FA:A1:5B:1D:68:0B:E9:5E:21:7D:83:62:AC:DB
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
    Signature Algorithm: sha256WithRSAEncryption
         8e:0c:50:18:5f:db:cc:80:5c:6e:ce:43:29:32:2e:0b:70:96:
         db:e8:23:c9:15:a2:99:72:d6:01:c9:61:8e:ed:8d:f8:4d:2f:
         99:57:bf:52:1f:4a:5b:7b:ff:24:23:5f:eb:3e:e8:8e:0c:d4:
         94:0f:20:a7:e3:3b:18:e9:76:06:5a:ae:65:38:d4:3a:98:d6:
         0b:73:5b:b5:8e:4c:b5:74:02:9a:9d:9a:7d:7a:18:2f:32:38:
         9e:0e:7b:de:15:3c:f1:33:e8:2d:3f:92:f0:f2:4e:7a:7f:e2:
         a5:2e:04:3a:2f:3b:1b:05:71:39:70:6d:a4:6e:8f:25:31:0e:
         2c:8a:7e:b4:30:7c:38:2f:48:df:19:56:42:4f:be:5f:d3:02:
         70:18:7e:76:66:ca:13:1c:e3:9c:4d:aa:d3:67:96:be:d9:49:
         5c:69:10:75:26:53:f7:50:39:06:15:d1:3a:87:47:f6:92:a2:
         d4:91:35:29:b7:4b:ea:56:4c:13:5e:32:7f:c7:3f:4c:46:67:
         54:8d:67:60:38:98:75:da:24:f2:64:b9:24:a1:e3:5b:42:66:
         4c:c7:cb:ee:c3:ca:bd:87:1b:7a:fc:35:53:2d:74:68:db:a7:
         47:db:03:a3:30:52:af:67:7f:54:a4:de:60:ca:ae:94:43:f8:
         98:85:fc:18:9b:b1:db:81:44:57:0b:be:6a:56:9d:2f:7d:75:
         c2:22:a4:7c:d7:ee:f8:de:10:11:26:60:35:1c:4c:87:2e:a2:
         fb:1f:5f:30:6c:11:c1:fa:f2:5b:46:02:0a:18:2f:02:a4:99:
         f2:43:29:cf:e6:5b:8a:d0:ec:42:bf:49:c6:8a:7e:b4:53:38:
         03:1b:fd:a9:49:88:b5:f1:42:93:c7:78:38:6c:2a:1c:be:83:
         97:27:b1:26:eb:16:44:ce:34:02:53:45:08:30:c9:3a:76:83:
         10:f3:af:c7:6f:0c:74:ec:81:ea:d9:c4:20:a5:1d:72:64:52:
         7b:e8:30:1a:9e:3a:05:9c:8a:69:e5:b7:43:b3:36:08:f2:e0:
         fb:88:d9:c1:b6:f4:4a:23:27:31:3a:51:b3:68:c9:6f:3e:f5:
         dd:98:4d:07:38:ed:f4:d3:ed:06:4c:84:87:3d:cf:f3:2e:e5:
         1a:b6:00:71:4c:51:35:c8:95:e4:c6:7e:82:47:d3:25:64:a4:
         0b:31:53:d0:e4:6b:97:98:21:4b:fc:e7:12:be:69:01:d8:b5:
         74:f5:b6:39:22:8a:8c:39:23:0f:be:4b:0f:9a:01:ac:b8:5b:
         12:cb:94:06:30:f5:74:45:20:af:ab:d6:af:21:0c:d8:62:84:
         18:c2:cf:4f:be:73:c9:33

Delete CA server certificate

OS10# crypto ca-cert delete Dell_rootCA1.crt
Successfully removed certificate

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\