Users Guide

Table Of Contents
If the system is in FIPS mode crypto fips enable command the CSR and private key are
generated using approved algorithms from a cryptographic library that has been validated against the
FIPS 140-2 standard. You can install the FIPS-compliant certificate-key pair using the crypto cert
install command with the fips option.
Examples
OS10# crypto cert generate request cert-file home://cert1.pem key-file
home://cee OS10-VM email admin@dell.com length 1024 altname DNS.dell.com
Processing certificate ...
Successfully created CSR file /home/admin/cert1.pem and key
OS10# crypto cert generate self-signed cert-file home://cert2.pem key-
file home:e OS10-VM email admin@dell.com length 1024 altname.dell.com
validity 365
Processing certificate ...
Successfully created certificate file /home/admin/cert2.pem and key
Supported
releases
10.4.3.0 or later
crypto cert install
Installs a host certificate and private key on the switch. A host certificate may be trusted from a CA or self-signed.
Syntax
crypto cert install cert-file cert-path key-file {key-path | private}
[password passphrase] [fips]
Parameters
cert-file cert-path Enter the local path to where the downloaded certificate is stored. You
can enter a full path or a relative path; for example, home://s4048-001-cert.pem or usb://
s4048-001-cert.pem or flash://certs/s4810-001-request.crt.
key-file {key-path | private} Enter the local path to retrieve the downloaded or locally
generated private key. Specify a key-path to install the key from a local directory. Enter private to
install the key from a local hidden location. After the certificate is successfully installed, the private
key is deleted from the specified key-path location and copied to the hidden location.
password passphrase (Optional) Enter the password used to decrypt the private key if it was
generated using a password.
fips (Optional) Install the certificate-key pair as FIPS-compliant. Enter fips to install a
certificate-key pair that a FIPS-aware application, such as RADIUS over TLS, uses. If you do not
enter fips, the certificate-key pair is stored as a non-FIPS compliant pair.
Default Not configured
Command mode EXEC
Usage
information
Before using the crypto cert install command, copy a CA-signed certificate to the home
directory on the switch using a secure connection, such as HTTPS, SCP, or SFTP, and (optionally) the
private key. To delete a trusted certificate, use the crypto cert delete command.
A successful installation of a trusted certificate requires that:
The downloaded certificate is correctly formatted.
The downloaded certificates public key corresponds to the private key.
You can assign an installed certificate-key pair to a security profile by entering the file name of the
certificate without an extension.
It is possible to store a certificate in either FIPS mode or non-FIPS mode on the switch, but not in both
modes, using the crypto cert install command and the optional fips option. You must ensure
that certificates installed in FIPS mode are compliant with the FIPS 140-2 standard.
Example
OS10# crypto cert install cert-file home://Dell_host1_CA1.pem key-file
home://Dell_host1_CA1.key
1382 Security