Send documentation comments to mdsfeedback-doc@cisco.com
43-13
Cisco MDS 9000 Family Fabric Manager Configuration Guide
OL-17256-03, Cisco MDS NX-OS Release 4.x
Chapter 43 Configuring Certificate Authorities and Digital Certificates
Configuring CAs and Digital Certificates
Note The challenge password is not saved with the configuration. This password is required in the
event that your certificate needs to be revoked, so you must remember this password.
Step 6 Click Apply Changes to save the changes.
Installing Identity Certificates
You receive the identity certificate from the CA by e-mail or through a web browser in base64 encoded
text form. You must install the identity certificate from the CA by cutting and pasting the encoded text.
To install an identity certificate received from the CA using Fabric Manager, follow these steps:
Step 1 Expand Switches > Security and then select PKI in the Physical Attributes pane.
Step 2 Click the Trust Point Actions tab, in the Information pane.
Step 3 Select the certimport option from the Command drop-down menu to import an identity certificate in
this trust point. The identity certificate is obtained from the corresponding CA for a CSR generated
previously (see
“Generating Certificate Requests” section on page 43-12).
Note The identity certificate should be available in PEM format in a file in bootflash.
Step 4 Enter the name of the certificate file that should have been copied to bootflash in the URL field in the
bootflash:filename format.
Step 5 Click Apply Changes to save your changes.
If successful, the values of the identity certificate and its related objects, like the certificate file name,
are automatically updated with the appropriate values as per the corresponding attributes in the identity
certificate.
Saving Your Configuration
Save your work when you make configuration changes or the information is lost when you exit.
To save your configuration using Fabric Manager, follow these steps:
Step 1 Expand Switches and then select Copy Configuration in the Physical Attributes pane.
Step 2 Select the switch configuration including the RSA key-pairs and certificates.
Step 3 Click Apply Changes to save the changes.