copy tftp flash

Downloads files from a TFTP server to the flash memory of a device.
Syntax
copy tftp flash { ipv4-address | ipv6-address } filename { certificate-data-file | client-certificate | client-private-key | fips-ufi-primary-sig | fips-ufi-secondary-sig | local-pri | local-sec | primary | secondary | ssh-pub-key-file | ssl-private-key-file | trust-certificate }
Parameters
ipv4-address
Specifies the IPv4 address of the TFTP server from where the file must be copied to the device.
ipv6-address
Specifies the IPv6 address of the TFTP server from where the file must be copied to the device.
filename
Specifies the name of the file that must be copied from the TFTP server.
certificate-data-file
Specifies that the file being copied is a digital certificate issued by a third-party Certificate Authority (CA).
client-certificate
Specifies that the file being copied is an RSA client certificate file.
client-private-key
Specifies that the file being copied is a client RSA private key file.
fips-ufi-primary-sig
Specifies that the file being copied is a FIPS primary unified file image (UFI) signature file.
fips-ufi-secondary-sig
Specifies that the file being copied is a FIPS secondary UFI signature file.
local-pri
Specifies the primary code image on the local unit.
local-sec
Specifies the secondary code image on the local unit.
primary
Specifies that the file being copied is a primary image file or a primary UFI file.
secondary
Specifies that the file being copied is a secondary image file or a secondary UFI file.
ssh-pub-key-file
Specifies the authorized public keys file
ssl-private-key-file
Specifies that the file eing copied is an SSL client private key file
trust-certificate
Specifies that the file being copied is an SSL trust certificate.
Modes

Privileged EXEC mode

Usage Guidelines

If the device has 8 MB of flash memory, you must delete the primary and secondary images.

RUCKUS recommends that you use the copy tftp flash command to copy the boot code to the device during a maintenance window. Attempting to do so during normal networking operations may cause disruption to the network.

If you use the fips-ufi-primary-sig or fips-ufi-secondary-sig keyword, the filename must be in ASCII text and must contain the .sig extension.

The unified file image (UFI) consists of the application image, the boot code image, and the signature in one unified file.

The .sig file must be used when FIPS is enabled to validate the unified image with the corresponding signature file.

UFI image download is supported using TFTP, USB, and SCP only.

Examples

The following example copies a primary image from the specified TFTP server location to the flash memory of the ICX device and shows system output on download progress.

device# copy tftp flash 10.176.6.93 GZR09000_b398ufi.bin primary
Parameter Validation Successful
Image Download started
............................Image Download Done
Image Validation Started
Image Write Done
Image Download Complete

The following example downloads a copy of a trusted certificate from the TFTP server to the ICX device flash.

device# copy tftp flash 10.198.137.230 SecureTrust_CA.pem trust-certificate
Parameter Validation Successful
....File Download Done
File Write Done
File Download Complete

The following example copies an image to the secondary flash memory.

device# copy tftp flash 10.2.3.4 SPR08080b1ufi.bin secondary

The following example copies a FIPS UFI signature file from the TFTP server to the primary flash memory.

device# copy tftp flash 10.37.2.40 signature_ufi.sig fips-ufi-primary-sig

The following example copies a FIPS UFI signature file from the TFTP server to the secondary flash memory.

device# copy tftp flash 10.37.2.40 signature_ufi.sig fips-ufi-secondary-sig

The following example copies a UFI image file from the TFTP server to the primary flash memory.

device# copy tftp flash 10.2.3.4 SPR08080b1ufi.bin primary

The following example imports a public key file from the TFTP server 192.168.10.1.

device# copy tftp flash 10.2.3.4 192.168.10.1 pkeys.txt ssh-pub-key-file

The following example imports a digital certificate issued by a third-party Certificate Authority (CA) and save it in the flash memory.

device# copy tftp flash 10.10.10.1 cacert.pem certificate-data-file

The following example shows how to import an SSL private key from a client.

device# copy tftp flash 192.168.9.210 keyfile ssl-private-key-file
History
Release version Command history
08.0.80 The command was modified to add the fips-ufi-primary-sig and fips-ufi-secondary-sig keywords, and to download a UFI file to flash memory.
08.0.90 The command was modified. The bootrom, fips-bootrom-sig, fips-primary-sig, fips-secondary-sig keywords were removed.
09.0.00 The command was modified. The ssh-pub-key-file, ssl-private-key-file, and certificate-data-file keywords were added. The private-key-file option was deprecated.