HP StorageWorks 2/32 Brocade Secure Fabric OS Administrator's Guide (53-100024 - Page 26

Verifying the Digital Certificate, Displaying the Digital Certificate Status

Page 26 highlights

2 3. If the Secure Fabric OS and Advanced Zoning licenses are already listed, the features are already available and the remaining steps are not required; continue if either license is not listed. 4. Contact the switch supplier to purchase the required license key. 5. After the key is received, type licenseAdd "key". key is the license key string exactly as provided by the switch supplier; it is case sensitive. You can copy it from the email in which it was provided directly into the CLI. switch:admin> licenseadd "aAaaaaAaAaAaAaA" adding license key "aAaaaaAaAaAaAaA" 6. Type the licenseShow command to verify that the license was successfully activated. If the license is listed, the feature is immediately available (the Secure Fabric OS license displays as "Security license"). Verifying the Digital Certificate Secure Fabric OS requires that each switch in the fabric has PKI objects and a digital certificate. Verify whether the objects and a digital certificate are correctly installed in the fabric (see "Displaying the Digital Certificate Status" on page 2-4). Displaying the Digital Certificate Status Use the pkishow command to display the status of the digital certificate and other PKI objects in the fabric. The digital certificate and other objects status displays Exists for passphrase, Private Key, CSR, Certificate, and Root Certificate when the certificate and objects are installed and ready. Use the following instructions to correct status when one or more of the items displays Empty: • If the certificate displays Empty but the other objects display Exist, follow the procedures in "Obtaining the Digital Certificate File" on page 2-7, then "Distributing Digital Certificates to the Switches" on page 2-13. • If all the object and certificate display Empty, create the objects on the switch as describe in "Creating PKI Objects" on page 2-5, then follow the instructions in "Obtaining the Digital Certificate File" on page 2-7 and "Distributing Digital Certificates to the Switches" on page 2-13. • If any of the other objects display Empty or the command displays an error message, re-create the objects as described in "Creating PKI Objects" on page 2-5. To verify that digital certificates are installed on all the switches in the fabric 1. Log in to one of the switches in the fabric as admin. 2. Display the PKI objects: • For Fabric OS v4.4.0, v5.01, v5.1.0, or v5.2.0 enter pkiShow. If the switch is a two-domain SilkWorm 24000, enter this command on both logical switches. • For Fabric OS v3.2.0, enter configShow "pki". 2-4 Secure Fabric OS Administrator's Guide Publication Number: 53-1000244-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118

2-4
Secure Fabric OS Administrator’s Guide
Publication Number: 53-1000244-01
2
3.
If the Secure Fabric OS and Advanced Zoning licenses are already listed, the features are already
available and the remaining steps are not required; continue if either license is not listed.
4.
Contact the switch supplier to purchase the required license key.
5.
After the key is received, type
licenseAdd “
key
.
key
is the license key string exactly as provided by the switch supplier; it is case sensitive. You can
copy it from the email in which it was provided directly into the CLI.
6.
Type the
licenseShow
command to verify that the license was successfully activated.
If the license is listed, the feature is immediately available (the Secure Fabric OS license displays as
“Security license”).
Verifying the Digital Certificate
Secure Fabric OS requires that each switch in the fabric has PKI objects and a digital certificate. Verify
whether the objects and a digital certificate are correctly installed in the fabric (see
“Displaying the
Digital Certificate Status”
on page 2-4).
Displaying the Digital Certificate Status
Use the
pkishow
command to display the status of the digital certificate and other PKI objects in the
fabric.
The digital certificate and other objects status displays Exists for passphrase, Private Key, CSR,
Certificate, and Root Certificate when the certificate and objects are installed and ready.
Use the following instructions to correct status when one or more of the items displays Empty:
If the certificate displays Empty but the other objects display Exist, follow the procedures in
“Obtaining the Digital Certificate File”
on page 2-7, then
“Distributing Digital Certificates to the
Switches”
on page 2-13.
If all the object and certificate display Empty, create the objects on the switch as describe in
“Creating PKI Objects”
on page 2-5, then follow the instructions in
“Obtaining the Digital
Certificate File”
on page 2-7 and
“Distributing Digital Certificates to the Switches”
on page 2-13.
If any of the other objects display Empty or the command displays an error message, re-create the
objects as described in
“Creating PKI Objects”
on page 2-5.
To verify that digital certificates are installed on all the switches in the fabric
1.
Log in to one of the switches in the fabric as admin.
2.
Display the PKI objects:
For Fabric OS v4.4.0, v5.01, v5.1.0, or v5.2.0 enter
pkiShow
. If the switch is a two-domain
SilkWorm 24000, enter this command on both logical switches.
For Fabric OS v3.2.0, enter
configShow “pki”
.
switch:admin>
licenseadd "aAaaaaAaAaAaAaA"
adding license key "aAaaaaAaAaAaAaA"