PKI Manual Import

To import X.509 certificates, you need the following items:

  1. Root CA Certificate, which will be used with the configured trustpoint on the TOE.
  2. The intermediate CA certificate.
  3. The local TOE certificate, which is signed by the RootCA or any intermediate CA of the RootCA.
  4. The key for the TOE's local certificate.

The listed certificates and keys should be copied into flash on the TOE.

Perform the following steps to import the certificates manually.

  1. Create a trustpoint. Here, the trustpoint corresponds to ROOT CA. Set the fingerprint for the trustpoint (which can be copied from the rootCA certificate).
    The following example provides the syntax for the commands.
    device# configure terminal
    device(config)# pki trustpoint < trustpointname >
    device(config-pki-trustpointname)# fingerprint < value >
    
    The following example creates a trustpoint called abcd and sets the fingerprint to the value copied from the rootCA certificate.
    device# configure terminal
    device(config)# pki trustpoint abcd
    device(config-pki-trustpoint-abcd)# fingerprint 3C:EA:EC:E6:F1:DD:3B:86:65:DE:58:F4:A2:75:D8:63:6D:23:68:40
    device(config-pki-trustpoint-abcd)# exit
    
  2. Import the key to the PKI database from flash memory of the FastIron device using one of the following command.

    Note: The key file can be a plain text or an encrypted file (encryption is recommended). Only aes256 encryption is supported for key file encryption.

    The following examples provide command syntax. The key type may be either rsa or ec.

    If the key file being used is plain text, the following command format should be used:

    device(config)# pki import key < keytype > < keylabel > pem url flash: < keyname >.key.pem
    

    If the key file is encrypted using a password, the following command format should be used:

    device(config)# pki import key < keytype > < keylabel > pem url flash: < keyname >.key.pem password pwd_value
    

    The following example imports the RSA key from the flash location specified.
    device(config)# pki import key rsa rsakey pem url flash: dut.key.pem
    device(config)# end
    
    The following example imports the EC key eckey1 from flash using a password string associated with the encrypted file. (You will be prompted for the password if you later try to open the imported file.)
    device(config)# pki import key ec eckey1 pem url flash: dut.eckey.pem password f1234yzztk!
    
  3. Use the following commands to import the CA and local certificates.
    The following example provides command syntax.
    device(config)# pki import < trustpointname > pem url flash: rootca.pem
    device(config)# pki import < trustpointname > pem url flash: localcert.pem
    
    The following command imports the CA certificate (rootca.pem) and the local certificate (localcert.pem) from the trustpoint named abcd.
    device(config)# pki import abcd pem url flash: rootca.pem
    device(config)# pki import abcd pem url flash: localcert.pem
    
  4. Attach the imported key label to the trustpoint using the following commands.
    The following example shows command syntax.
    device(config)# pki trustpoint < trustpointname >
    device(config-pki-trustpoint-trustpointname)# { rsakeypair | eckeypair } key-label <label >
    
    The following example binds the rsakey label to the CA trustpoint named abcd.
    device(config)# pki trustpoint abcd
    device(config-pki-trustpoint-abcd)# rsakeypair key-label rsakey
    
  5. Authenticate the rootCA trustpoint using the following command.
    The following example provides the syntax for authenticating the trustpoint.
    device(config-pki-trustpoint-trustpointname)# exit
    device(config)# pki authenticate < trustpointname >
    
    The following example authenticates the previously configured trustpoint abcd.
    device(config-pki-trustpoint-abcd)# exit
    device(config)# pki authenticate abcd
    
    Note: Because the manual process does not generate a CSR on the FastIron device (the TOE), it is not necessary to execute the pki enroll command. after the trustpoint is authenticated.
  6. Use the following commands to check the local and CA certificates on the FastIron device.
    device(config)# show pki certificates local
    device(config)# show pki certificates trustpoint < trustpointname >
    
    The following example displays information for the local certificate and for certificates from the trustpoint abcd.
    device# show pki certificates local
    
    ----------------PKI LOCAL CERTIFICATE ENTRY-----------------
    CA: TLS-ABCD
    Certificate:
        Data:
            Version: 3 (0x2)
            Serial Number: 4125 (0x101d)
        Signature Algorithm: sha256WithRSAEncryption
            Issuer: C=US, ST=CA, L=SJ, O=ROOTCA-CC, OU=SQA, CN=ROOTCA-CC/emailAddress=user@arris.com
            Validity
                Not Before: Nov  7 02:24:18 2017 GMT
                Not After : Nov 17 02:24:18 2018 GMT
            Subject: CN=DUTFIPSCC, ST=CA, C=US/emailAddress=user@arris.com, O=DUTFIPSCC, OU=SQA
    device#
    
    
    device# show pki certificates trustpoint
    
    ----------------PKI TRUSTPOINT CERTIFICATE ENTRY-----------------
    CA: TLS-ABCD
    Certificate:
        Data:
            Version: 3 (0x2)
            Serial Number:
                bd:fa:4f:da:bd:89:4a:5d
        Signature Algorithm: sha256WithRSAEncryption
            Issuer: C=US, ST=CA, L=SJ, O=ROOTCA-CC, OU=SQA, CN=ROOTCA-CC/emailAddress=user@arris.com
            Validity
                Not Before: Nov  7 02:10:00 2017 GMT
                Not After : Nov  7 02:10:00 2022 GMT
            Subject: C=US, ST=CA, L=SJ, O=ROOTCA-CC, OU=SQA, CN=ROOTCA-CC/emailAddress=user@arris.com
    device#
    
  7. Validate the certificates using the following command.
    The following example provides the syntax for validating the imported certificates.
    device(config)# pki cert-validate < trustpointname >
    
    The following example successfully validates certificates imported from the trustpoint abcd.
    device(config)# pki cert-validate abcd
    PKI: Successfully validated the local certificate for trustpoint: abcd
    

The following example imports certificates for the configured trustpoint abcd, authenticates the trustpoint, and validates imported certificates.

device# configure terminal
device(config)# crypto key generate rsa
device(config)# pki import key rsa rsakey pem url flash: dut.key.pem
device(config)# pki import abcd pem url flash: rootca.pem
device(config)# pki import abcd pem url flash: localcert.pem
device(config)# pki trustpoint abcd
device(config-pki-trustpoint-abcd)# ocsp http post
device(config-pki-trustpoint-abcd)# revocation-check ocsp
device(config-pki-trustpoint-abcd)# ocsp-url http://10.21.40.39:2560
device(config-pki-trustpoint-abcd)# fingerprint 3C:EA:EC:E6:F1:DD:3B:86:65:DE:58:F4:A2:75:D8:63:6D:23:68:40
device(config-pki-trustpoint-abcd)# exit
device(config)# pki authenticate abcd
device(config)# pki cert-validate abcd
PKI: Successfully validated the local certificate for trustpoint: abcd