A SERVICE OF

logo

392 CHAPTER 13: CRYPTOGRAPHY COMMANDS
Usage — To use this command, you must already have generated a
certificate request with the crypto generate request command, sent
the request to the certificate authority, and obtained a signed copy of the
WX switch certificate as a PKCS #7 object file. Then do the following:
1 Open the PKCS #7 object file with an ASCII text editor such as Notepad
or vi.
2 Enter the crypto certificate command on the CLI command line.
3 When MSS prompts you for the PEM-formatted certificate, paste the
PKCS #7 object file onto the command line.
The WX switch verifies the validity of the public key associated with this
certificate before installing it, to prevent a mismatch between the WX
switch’s private key and the public key in the installed certificate.
Examples — The following command installs a certificate:
WX4400# crypto certificate admin
Enter PEM-encoded certificate
-----BEGIN CERTIFICATE-----
MIIBdTCP3wIBADA2MQswCQYDVQQGEwJVUzELMAkGA1UECBMCQOExGjAYBgNVBAMU
EXR1Y2hwdWJzQHRycHouY29tMIGfMAOGCSqGSIb3DQEBAQAA4GNADCBiQKBgQC4
.....
2L8Q9tk+G2As84QYLm8wmVY>xP56M;CUAm908C2foYgOY40=
-----END CERTIFICATE-----
See Also
“crypto generate request” on page 393
“crypto generate self-signed” on page 395
crypto generate key Generates an RSA public-private encryption key pair that is required for a
Certificate Signing Request (CSR) or a self-signed certificate.
Syntax
crypto generate key {admin | eap | ssh | webaaa }
{512 | 1024 | 2048}
admin — Generates an administrative key pair for authenticating the
WX switch to 3WXM or Web Manager.
eap — Generates an EAP key pair for authenticating the WX switch to
802.1X supplicants (clients).