D-Link dws-1008 Switch User Manual


 
D-Link DWS-1008 CLI Manual 222
crypto otp
Sets a one-time password (OTP) for use with the crypto pkcs12 command.
Syntax: crypto otp {admin | eap | web} one-time-password
admin Creates a one-time password for installing a PKCS#12 object file for an
administrative certificate and key pair—and optionally the certificate
authority’s own certificate—to authenticate the switch to Web View.
eap Creates a one-time password for installing a PKCS#12 object file for an EAP
certificate and key pair—and optionally the certificate authority’s own
certificate—to authenticate the switch to 802.1X supplicants (clients).
web Creates a one-time password for installing a PKCS#12 object file for a
WebAAA certificate and key pair—and optionally the certificate authority’s
own certificate—to authenticate the switch to WebAAA clients.
one-time-password Password of at least 1 alphanumeric character, with no spaces, for clients
other than Microsoft Windows clients. The password must be the same as
the password protecting the PKCS#12 object file.
Note: On a switch that handles communications to and from Microsoft
Windows clients, use a one-time password of 31characters or fewer.
The following characters cannot be used as part of the one-time password
of a PKCS#12 file:
• Quotation marks (“”)
• Question mark (?)
• Ampersand (&)
Defaults: None.
Access: Enabled.
Usage: The password allows the public-private key pair and certificate to be installed together
from the same PKCS#12 object file. MSS erases the one-time password after processing the
cryptopkcs12 command or when you reboot the switch.
D-Link recommends that you create a password that is memorable to you but is not subject
to easy guesses or a dictionary attack. For best results, create a password of alphanumeric
uppercase and lowercase characters.
Examples: The following command creates the one-time password hap9iN#ss for installing an
EAP certificate and key pair:
DWS-1008# crypto generate otp eap hap9iN#ss
OTP set