D-Link DES-3010PA-TAA CLI Guide - Page 324

crypto certificate generate, crypto certificate, generate [key-generate, passphrase, duration

Page 324 highlights

D-Link DES-3010FA/GA/PA CLI Reference Guide crypto certificate generate The crypto certificate generate Global Configuration mode command generates self signed certificate for HTTPS . Syntax crypto certificate number generate [key-generate [length]] [passphrase string] [cn common- name] [ou organization-unit] [or organization] [loc location] [st state] [cu country] [duration days] Parameters • number - Specifies the certificate number. If unspecified, defaults to 1. (Range: 1-2) • key-generate - Regenerate SSL RSA key. • length - Specifies the length of the SSL's RSA key. If unspecified, length defaults to 1024. (Range: 512 - 2048) • passphrase string - Passphrase that is used for exporting the certificate in PKCS12 file format. If unspecified the certificate is not exportable. (Range: 8-96) • cn common- name - Specifies the fully qualified URL or IP address of the device. If unspecified, defaults to the lowest IP address of the device (when the certificate is generated). (Range: 1-64) • ou organization-unit - Specifies the organization-unit or department name. (Range: 1-64) • or organization - Specifies the organization name. (Range: 1-64) • loc location - Specifies the location or the city name. (Range: 1-64) • st state - Specifies the state or province name. • cu country - Specifies the country name. (Range: 2) • duration days - Specifies number of days a certification would be valid. If unspecified defaults to 365 days. (Range: 30-3650) Default Configuration The Certificate and the SSL's RSA key pairs do not exist. Command Mode Global Configuration mode User Guidelines Use this command to generate self-signed certificate for your device. This command is not saved in the router configuration; however, the certificate and keys generated by this command are saved in the private configuration (which is never displayed to the user or backed up to another device). When you export an RSA key pair to a PKCS#12 file, the RSA key pair is as secure as the passphrase, keep the passphrase secure. If the RSA keys doesn't exist, the parameter key-generate must be used. Page 323

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361

D-Link DES-3010FA/GA/PA CLI Reference Guide
Page 323
crypto certificate generate
The
crypto certificate generate
Global Configuration mode command generates self signed certificate for
HTTPS .
Syntax
crypto certificate
number
generate [key-generate [
length
]] [passphrase
string
] [cn
common- name
] [ou o
rga-
nization-unit
] [or
organization
] [loc
location
] [st
state
] [cu
country
] [duration
days
]
Parameters
number
- Specifies the certificate number. If unspecified, defaults to 1. (Range: 1-2)
key-generate
- Regenerate SSL RSA key.
length
- Specifies the length of the SSL's RSA key. If unspecified, length defaults to 1024. (Range: 512 -
2048)
passphrase
string
- Passphrase that is used for exporting the certificate in PKCS12 file format. If unspecified
the certificate is not exportable. (Range: 8-96)
cn
common- name
- Specifies the fully qualified URL or IP address of the device. If unspecified, defaults to
the lowest IP address of the device (when the certificate is generated). (Range: 1-64)
ou
organization-unit
- Specifies the organization-unit or department name. (Range: 1-64)
or
organization
- Specifies the organization name. (Range: 1-64)
loc
location
- Specifies the location or the city name. (Range: 1-64)
st
state
- Specifies the state or province name.
cu
country
- Specifies the country name. (Range: 2)
duration
days
- Specifies number of days a certification would be valid. If unspecified defaults to 365 days.
(Range: 30-3650)
Default Configuration
The Certificate and the SSL's RSA key pairs do not exist.
Command Mode
Global Configuration mode
User Guidelines
Use this command to generate self-signed certificate for your device.
This command is not saved in the router configuration; however, the certificate and keys generated by this com-
mand are saved in the private configuration (which is never displayed to the user or backed up to another device).
When you export an RSA key pair to a PKCS#12 file, the RSA key pair is as secure as the passphrase, keep the
passphrase secure.
If the RSA keys doesn't exist, the parameter key-generate must be used.