Access Security Guide K/KA/KB.15.15

Syntax
Definitions
ta-certificate
Copy a Trust Anchor certificate to the device.
ta-profile-name
The Trust Anchor Profile associated with the certificate.
ip-addr
IP address of the server.
file-name
Name of the certificate file.
ipv6-addr
Specify TFTP server IPv6 address.
host-name-str
Specify hostname of the SFTP server.
user
Specify the username on the remote system.
username@ip-str
Specify the username along with remote system information (hostname, IPv4 or
IPv6 address.)
port
TCP port of the SSH server on the remote system.
Syntax
Copy a Trust Anchor (TA) certificate to the device.
Copy tftp local-certificate [Cert-Name][ta-profile-name][user
<user-name>]
[<ip-addr/ipv6-addr/host-name-str>][username@ip-str
<filename>][port <1-65535>]
The file is checked immediately upon completion of transfer and results written to
the CLI. The file can be in PEM-encoded or DER-encoded (binary) PKCS#7 format.
If the certificate subject matches an existing TA certificate associated with the
specified TA profile, then the new certificate updates the existing certificate.
Loading a local certificate
To load a local certificate (single certificate/certificate chain), execute the following command.
Syntax
(Switch_Name#)copy tftp local-certificate
<ip-addr><file-name>
(Switch_Name#)copy sftp local-certificate [user
<user-name>][<ip-addr/ipv6-addr/host-name-str>][<username@ip-str>]<filename>[port
<1-65535>]
Definitions
ta-certificate
Copy a Trust Anchor certificate to the device.
512 Certificate manager