HP StorageWorks 2/16V Brocade Secure Fabric OS Administrator's Guide (53-10002 - Page 42

Accessing PKI Certificate Help, To access PKI help

Page 42 highlights

2 2-20 Accessing PKI Certificate Help The purpose of PKI help is to obtain command line information about PKICert and obtain advice on advanced options for advanced users. To access PKI help 1. Select option 4 (as shown in the following example) and follow the screen prompts: PKI CERTIFICATE INSTALLATION UTILITY pki_v1.0.6 FUNCTIONS 1) Retrieve CSRs from switches & write a CSR file 2) Install Certificates contained in a Certificate file 3) Generate a Licensed-Product/Installed-Certificates report 4) Help using PKI-Cert to get & install certificates q) Quit PKI Certificate installation utility Enter choice> 4 HELP USING PKI-CERT TO GET & INSTALL DIGITAL CERTIFICATIONS NOTE:This utility will only work with switches running a FAB-OS version that supports Fabric Security (e.g. >= v2.6, v3.2, v4.3) 1) Use PKI-Cert to get CSR's (Certificate Signing Requests) which will be written to a data file. The XML format file will contain CSR's for each switch (identified by its WWN). 2) Next, Upload the CSR file to the Brocade Security Upgrade website. A data file will be emailed to you containing a set of digital Certificates, one for each switch, in XML format. 3) Finally, use PKI-Cert to install the Certificates. You will be prompted for the name of the data file containing the certificates. Some options may be given on the command line such as "Log-Level." Read help for Batch/Command-Line mode usage (y/n)? > y HELP WITH COMMAND LINE USEAGE OF PKI CERTIFICATE UTILITY pkicert [-gGil] [_e log-file] [-d data-file] [-a addr-file] [-A switch-addr] [-L log-level] [-u user-login -p password] Task Options: -g Get CSRs & generate a CSR data file -G Get CSRs (even from switches with certificates) -i Install Certificates from a data file -l Licensed Product Report compile & generate If none of the above "task" options is given, Pki-Cert will operate in "Interactive" rather than "Batch" mode. Other OPtions: Log-file: -e (events/errors log) Path/file-name of log file created and written to (or if it already exists, apprended to ) with event/error data Secure Fabric OS Administrator's Guide Publication Number: 53-1000244-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118

2-20
Secure Fabric OS Administrator’s Guide
Publication Number: 53-1000244-01
2
Accessing PKI Certificate Help
The purpose of PKI help is to obtain command line information about PKICert and obtain advice on
advanced options for advanced users.
To access PKI help
1.
Select option
4
(as shown in the following example) and follow the screen prompts:
PKI CERTIFICATE INSTALLATION UTILITY pki_v1.0.6
FUNCTIONS
1)
Retrieve CSRs from switches & write a CSR file
2)
Install Certificates contained in a Certificate file
3)
Generate a Licensed-Product/Installed-Certificates report
4)
Help using PKI-Cert to get & install certificates
q)
Quit PKI Certificate installation utility
Enter choice>
4
HELP USING PKI-CERT TO GET & INSTALL DIGITAL CERTIFICATIONS
NOTE:This utility will only work with switches running a FAB-OS version
that supports Fabric Security (e.g. >= v2.6, v3.2, v4.3)
1)
Use PKI-Cert to get CSR’s (Certificate Signing Requests) which will be
written to a data file. The XML format file will contain CSR’s for each
switch (identified by its WWN).
2)
Next, Upload the CSR file to the Brocade Security Upgrade website. A data
file will be emailed to you containing a set of digital Certificates, one
for
each switch, in XML format.
3)
Finally, use PKI-Cert to install the Certificates. You will be prompted for
the name of the data file containing the certificates.
Some options may be given on the command line such as “Log-Level.”
Read help for Batch/Command-Line mode usage (y/n)? >
y
HELP WITH COMMAND LINE USEAGE OF PKI CERTIFICATE UTILITY
pkicert [-gGil] [_e log-file] [-d data-file] [-a addr-file] [-A switch-addr] [-L
log-level] [-u user-login -p password]
Task Options:
-g Get CSRs & generate a CSR data file
-G Get CSRs (even from switches with certificates)
-i Install Certificates from a data file
-l Licensed Product Report compile & generate
If none of the above “task” options is given, Pki-Cert will operate in
“Interactive” rather than “Batch” mode.
Other OPtions:
Log-file: -e (events/errors log)
Path/file-name of log file created and written to (or if it already exists,
apprended to ) with event/error data
<Press Enter to Continue>