Access Security Guide K/KA/KB.15.15

Options
key-size [1024|2048]
The length of the RSA key, default is 1024 bits.
Definitions
certificate-name
Name of the certificate.
ta-profile
The Trust Anchor Profile associated with the certificate. A profile named default’
is updateable from the web UI.
ta-profile-name
Specify the Switch Id TA profile name.
useage[<openflow|web|all>]
Intended application for the certificate, the default is web.
valid-start
Certificate validity start date (MM/DD/YY).
valid-end
Certificate validity end date (MM/DD/YY).
Subject fields
cn-value
Common Name (CN) – must be present, max length 100.
org-value
Organization Name (O) – preferred, max length 100.
org-unit value
Organizational Unit Name (OU) – preferred, max length 100.
location-value
Locality (L) – optional, max length 100.
state-value
State (ST) – optional, max length 100.
country-code
To specify the two letter ISO 3166-1 country code. Max length 2.
NOTE: A CSR created with TA profile name of ‘default’ MUST include usage of
either “web” or “all”.
Example of PEM format output
This command creates a certificate signing request in realtime and then output the
result to the console in openSSL compatible PEM format:
-----BEGIN CERTIFICATE REQUEST-----
MIIBpDCCAQ0CAQAwZDELMAkGA1UEBhMCVVMxCzAJBgNVBAgTAkNBMRIwEAYDVQQH
EwlSb3NldmlsbGUxCzAJBgNVBAoTAkhQMQ0wCwYDVQQLEwRFVlBHMRgwFgYDVQQD
Ew9UZXN0IE1hY2hpbmUgMDEwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAN7i
w3x2gi3tZf4LnXltSicl7RNcVggxYHcZQySWFtCXFTb5uaJ6vA3RdBIThgUKZSpc
rgtc7jQmRDUdKAbWLPrqC7wBxMlXbnQYegubvOfzf/dT1CYJXxdUZh5BMN5ob/00
t60m9cM7Odsu0a0dBoQQRI8315KJ0AuHDE6VOe4dAgMBAAGgADANBgkqhkiG9w0B
AQUFAAOBgQBQCZar2ox6RXm7F/vVhyrrp0E0YrPimxDvg40jnwqtwOgpQAvns4pt
o5RVx4/Q6hzF2QivYqLl3+K8WOVVJ7XLDcHNea8RJgx13t45uMYrsMKWdbhR9+jQ
Local certificate enrollment – manual mode 507