Users Guide

Switch Management Commands 2327
-----END CERTIFICATE REQUEST-----
crypto certificate import
Use the crypto certificate import command in Global Configuration mode to
import a certificate signed by the Certification Authority for HTTPS.
Syntax
crypto certificate number import
number — Specifies the certificate number. (Range: 1–2)
Default Configuration
This command has no default configuration.
Command Mode
Global Configuration mode
User Guidelines
Use this command to enter an external certificate (signed by the Certification
Authority) to the switch. To end the session, add a period (.) on a separate
line after the input, and press ENTER.
The imported certificate must be based on a certificate request created by the
crypto certificate request Privileged Exec command.
If the public key found in the certificate does not match the switch's SSL RSA
key, the command fails.
Regenerating the RSA key will render existing certificates invalid.
Certificates are validated on input. The system log will show any encountered
certificate errors such as invalid format or if the certificate could not be
validated against the switch private key. Invalid certificates are not imported.
The signed certificate must contain the switch public key and match the RSA
key on the switch and must be in X509 PEM text format.
This command is not saved in the router configuration; however, the
certificate imported by this command is saved in the private configuration.
Certificates are propagated across the stack.