HP StorageWorks MSA 2/8 HP StorageWorks Secure Fabric OS V1.0 User Guide (AA-R - Page 39

Re-creating PKI Objects If Required, Distributing Digital Certificates to the, Switches

Page 39 highlights

Adding Secure Fabric OS to the Fabric switch:admin> pkishow Passphrase : Exist Private Key : Exist CSR : Exist Certificate : Exist Root Certificate: Exist switch:admin> Displaying PKI objects on Fabric OS v2.6.1 and v3.1.x: switch:admin> configshow "pki" Passphrase : Exist Private Key : Exist CSR : Exist Certificate : Exist Root Certificate: Exist switch:admin> 3. Verify that Certificate shows Exist. If the certificate shows as Empty, but the other objects show as Exist, repeat the procedure provided in "Distributing Digital Certificates to the Switches" on page 35. If any of the other objects show as Empty, re-create them as described in "Re-creating PKI Objects If Required" on page 39. 4. Repeat this procedure for the remaining switches in the fabric. Re-creating PKI Objects If Required The PKI objects (except for the digital certificate) are automatically generated the first time Fabric OS v2.6.1, v3.1.x, or v4.1.x is booted. If any of the PKI objects appears to be missing, the switch segments from the fabric. The PKI objects on Fabric OS v2.6.1, v3.1.x, and v4.1.x can be regenerated by rebooting the switch. In addition, the PKI objects on Fabric OS v4.1.x can be regenerated through the CLI. To use the CLI to re-create the PKI objects on Fabric OS v4.1.x: Note: Secure Mode must be disabled to perform this procedure. 1. Log into the switch as Admin. Secure Fabric OS Version 1.0 User Guide 39

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129

Adding Secure Fabric OS to the Fabric
39
Secure Fabric OS Version 1.0 User Guide
Displaying PKI objects on Fabric OS v2.6.1 and v3.1.x:
3.
Verify that
Certificate
shows
Exist
.
If the certificate shows as
Empty
, but the other objects show as
Exist
,
repeat the procedure provided in “
Distributing Digital Certificates to the
Switches
” on page 35.
If any of the other objects show as
Empty
, re-create them as described in
Re-creating PKI Objects If Required
” on page 39.
4.
Repeat this procedure for the remaining switches in the fabric.
Re-creating PKI Objects If Required
The PKI objects (except for the digital certificate) are automatically generated the
first time Fabric OS v2.6.1, v3.1.x, or v4.1.x is booted. If any of the PKI objects
appears to be missing, the switch segments from the fabric. The PKI objects on
Fabric OS v2.6.1, v3.1.x, and v4.1.x can be regenerated by rebooting the switch.
In addition, the PKI objects on Fabric OS v4.1.x can be regenerated through the
CLI.
To use the CLI to re-create the PKI objects on Fabric OS v4.1.x:
Note:
Secure Mode must be disabled to perform this procedure.
1.
Log into the switch as Admin.
switch:admin> pkishow
Passphrase
: Exist
Private Key
: Exist
CSR
: Exist
Certificate
: Exist
Root Certificate: Exist
switch:admin>
switch:admin> configshow “pki”
Passphrase
: Exist
Private Key
: Exist
CSR
: Exist
Certificate
: Exist
Root Certificate: Exist
switch:admin>