Users Guide

Table Of Contents
Example
OS10(config)# crypto security-profile profile-1
OS10(config-sec-profile)# peer-name-check
OS10(config)# crypto security-profile profile-1
OS10(config-sec-profile)# no peer-name-check
Supported
releases
10.5.0 or later
revocation-check
Enables CRL checking in a security profile.
Syntax
revocation-check
Parameters None
Default Not configured
Command mode SEC-PROFILE
Usage
information
Use the revocation-check command to enable the verification of certificates presented by external
devices for a PKI-enablled application on the switch. Use the show crypto crl command to display
the CRLs installed on the switch and used to ensure the validity and trustworthiness of certificates from
external devices. The no version of the command disables CRL checking in a security profile.
Example
OS10(config)# crypto security-profile profile-1
OS10(config-sec-profile)# revocation-check
OS10(config)# crypto security-profile profile-1
OS10(config-sec-profile)# no revocation-check
Supported
releases
10.5.0 or later
show crypto ca-certs
Displays all CA certificates installed on the switch.
Syntax
show crypto ca-certs [filename]
Parameters filename (Optional) Enter the text filename of a CA certificate as shown in the show crypto
ca-certs output. Enter the filename in the format filename.crt.
Default Display all installed CA certificates.
Command mode EXEC
Usage
information
To delete a CA certificate, use the crypto ca-cert delete command. Enter the filename as shown
in the show crypto ca-certs output.
Example
OS10# show crypto ca-certs
--------------------------------------
| Locally installed certificates |
--------------------------------------
Dell_interCA1.crt
Dell_rootCA1.crt
OS10# show crypto ca-certs Dell_interCA1.crt
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 4096 (0x1000)
Signature Algorithm: sha256WithRSAEncryption
Security 1385