Users Guide

Table Of Contents
To import a CA server certificate:
1. Use the copy command to download an X.509v3 certificate created by a CA server using a secure method, such as HTTPS,
SCP, or SFTP. Copy the CA certificate to the local directory on the switch, such as home:// or usb://.
2. Use the crypto ca-cert install command to install the certificate. When you install a CA certificate, specify the local
path where the certificate is stored.
The switch verifies the certificate and installs it in an existing directory of trusted certificates in PEM format.
Install CA certificate
Install a CA certificate in EXEC mode.
crypto ca-cert install ca-cert-filepath [filename]
ca-cert-filepath specifies the local path to the downloaded certificate; for example, home://CAcert.pem or
usb://CA-cert.pem.
filename specifies an optional filename that the certificate is stored under in the OS10 trust-store directory. Enter the
filename in the filename.crt format.
Example: Download and install CA certificate
OS10# copy scp:///tftpuser@10.11.178.103:/tftpboot/certs/Dell_rootCA1.pem home://
Dell_rootCA1.pem
password:
OS10# crypto ca-cert install home://Dell_rootCA1.pem
Processing certificate ...
Installed Root CA certificate
CommonName = Dell_rootCA1
IssuerName = Dell_rootCA1
Display CA server certificate
OS10# show crypto ca-certs
--------------------------------------
| Locally installed certificates |
--------------------------------------
Dell_rootCA1.crt
OS10# show crypto ca-certs Dell_rootCA1.crt
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
95:48:23:17:76:9d:05:e1
Signature Algorithm: sha256WithRSAEncryption
Issuer: C = US, ST = California, L = Santa Clara, O = Dell EMC, OU = Networking,
CN = Dell_rootCA1
Validity
Not Before: Jul 25 18:21:50 2018 GMT
Not After : Jul 20 18:21:50 2038 GMT
Subject: C = US, ST = California, L = Santa Clara, O = Dell EMC, OU =
Networking, CN = Dell_rootCA1
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (4096 bit)
Modulus:
00:cd:9d:ca:10:6b:b1:54:81:10:92:42:9f:6a:cb:
49:51:9d:46:10:cb:67:08:2b:75:2a:62:40:80:a3:
f5:7d:58:67:f4:cc:c6:70:32:14:4c:f0:4d:cd:7e:
0d:5c:63:28:5e:6c:ad:9e:13:13:71:6d:9d:10:a9:
a1:d8:6b:bd:a3:a0:5a:11:19:87:4d:3d:08:6f:10:
03:df:70:89:5f:b7:56:49:32:57:9c:28:5e:43:7f:
ca:bc:41:c7:31:51:97:7f:73:b7:b0:c4:13:21:e6:
2c:4c:19:fd:35:0b:26:16:78:fc:c3:73:21:3a:06:
f6:ec:87:3f:9f:5e:3a:0c:23:5e:13:4c:9e:5a:70:
18:d4:ad:cb:cf:47:c1:c6:50:a0:49:df:a0:a6:47:
1e:13:19:49:9e:67:db:1c:c7:23:9e:37:3b:c7:0c:
cd:26:46:f6:c1:e1:93:64:29:81:9c:e9:a8:1d:29:
19:4c:8d:a4:a8:53:66:2b:b2:70:ff:ec:80:d4:87:
Security
1167