HP StorageWorks 2/16V Brocade Secure Fabric OS Administrator's Guide (53-10002 - Page 28

Removing PKI Objects, To remove PKI objects in unsecured mode

Page 28 highlights

2 4. Type the pkiShow command. If the switch is a two-domain SilkWorm 24000, enter this command on both logical switches. switch:admin> pkishow Passphrase : Exist Private Key : Exist CSR : Exist Certificate : Empty Root Certificate: Exist The command displays the status of the PKI objects. 5. Repeat for any other switches, as required. Removing PKI Objects You cannot delete PKI objects in secure mode. If they are deleted when secure mode is disabled, secure mode cannot be re-enabled until they are generated. If any PKI objects are missing, all the PKI objects should be deleted using the pkiRemove command and then regenerated using the pkiCreate command or by rebooting the switch (any missing PKI objects, except the digital certificate, are automatically regenerated when the switch is rebooted). If the digital certificate is deleted, it must be reinstalled on the switch according to the instructions provided in "Distributing Digital Certificates to the Switches" on page 2-13. For Fabric OS v3.2.0, use configRemove to remove all the PKI objects, type configUpload, and then fastboot the switch. After the switch reboots, all PKI objects are available except for the certificate. To remove PKI objects in unsecured mode switch:admin> pkiremove WARNING!!! Removing Pki objects will impair the security functionality of this fibre channel switch. If you want secure mode enabled, you will need to get the switch certificate again. About to remove Pki objects. ARE YOU SURE (yes, y, no, n): [no] y All PKI objects removed. If run in secure mode, the following error message is displayed: switch:admin> pkiremove This Switch is in secure mode. Removing Pki objects is not allowed. Exiting... 2-6 Secure Fabric OS Administrator's Guide Publication Number: 53-1000244-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118

2-6
Secure Fabric OS Administrator’s Guide
Publication Number: 53-1000244-01
2
4.
Type the
pkiShow
command. If the switch is a two-domain SilkWorm 24000, enter this command
on both logical switches.
The command displays the status of the PKI objects.
5.
Repeat for any other switches, as required.
Removing PKI Objects
You cannot delete PKI objects in secure mode. If they are deleted when secure mode is disabled, secure
mode cannot be re-enabled until they are generated. If any PKI objects are missing, all the PKI objects
should be deleted using the
pkiRemove
command and then regenerated using the
pkiCreate
command
or by rebooting the switch (any missing PKI objects, except the digital certificate, are automatically
regenerated when the switch is rebooted). If the digital certificate is deleted, it must be reinstalled on the
switch according to the instructions provided in
“Distributing Digital Certificates to the Switches”
on
page 2-13.
For Fabric OS v3.2.0, use
configRemove
to remove all the PKI objects, type
configUpload
, and then
fastboot the switch. After the switch reboots, all PKI objects are available except for the certificate.
To remove PKI objects in unsecured mode
If run in secure mode, the following error message is displayed:
switch:admin>
pkishow
Passphrase
: Exist
Private Key
: Exist
CSR
: Exist
Certificate
: Empty
Root Certificate: Exist
switch:admin>
pkiremove
WARNING!!!
Removing Pki objects will impair the security functionality
of this fibre channel switch. If you want secure mode enabled,
you will need to get the switch certificate again.
About to remove Pki objects.
ARE YOU SURE (yes, y, no, n): [no]
y
All PKI objects removed.
switch:admin>
pkiremove
This Switch is in secure mode.
Removing Pki objects is not allowed. Exiting...