PKI Manual Import
To import X.509 certificates, you need the following items:
- Root CA Certificate, which will be used with the configured trustpoint on the TOE.
- The intermediate CA certificate.
- The local TOE certificate, which is signed by the RootCA or any intermediate CA of the RootCA.
- The key for the TOE's local certificate.
The listed certificates and keys should be copied into flash on the TOE.
Perform the following steps to import the certificates manually.
- Create a trustpoint. Here, the trustpoint corresponds to ROOT CA. Set the fingerprint
for the trustpoint (which can be copied from the rootCA certificate).
The following example provides the syntax for the commands.
device# configure terminal device(config)# pki trustpoint < trustpointname > device(config-pki-trustpointname)# fingerprint < value >
The following example creates a trustpoint called abcd and sets the fingerprint to the value copied from the rootCA certificate. - Import the key to the PKI database from flash memory of the FastIron device using
one of the following command.
Note: The key file can be a plain text or an encrypted file (encryption is recommended). Only aes256 encryption is supported for key file encryption.
The following examples provide command syntax. The key type may be either rsa or ec.
If the key file being used is plain text, the following command format should be used:
device(config)# pki import key < keytype > < keylabel > pem url flash: < keyname >.key.pem
If the key file is encrypted using a password, the following command format should be used:
device(config)# pki import key < keytype > < keylabel > pem url flash: < keyname >.key.pem password pwd_value
The following example imports the RSA key from the flash location specified.The following example imports the EC key eckey1 from flash using a password string associated with the encrypted file. (You will be prompted for the password if you later try to open the imported file.) - Use the following commands to import the CA and local certificates.
The following example provides command syntax.
device(config)# pki import < trustpointname > pem url flash: rootca.pem device(config)# pki import < trustpointname > pem url flash: localcert.pem
The following command imports the CA certificate (rootca.pem) and the local certificate (localcert.pem) from the trustpoint named abcd. - Attach the imported key label to the trustpoint using the following commands.
The following example shows command syntax.
device(config)# pki trustpoint < trustpointname > device(config-pki-trustpoint-trustpointname)# { rsakeypair | eckeypair } key-label <label >The following example binds the rsakey label to the CA trustpoint named abcd. - Authenticate the rootCA trustpoint using the following command.
The following example provides the syntax for authenticating the trustpoint.
device(config-pki-trustpoint-trustpointname)# exit device(config)# pki authenticate < trustpointname >
The following example authenticates the previously configured trustpoint abcd. - Use the following commands to check the local and CA certificates on the FastIron
device.
device(config)# show pki certificates local device(config)# show pki certificates trustpoint < trustpointname >
The following example displays information for the local certificate and for certificates from the trustpoint abcd.device# show pki certificates local ----------------PKI LOCAL CERTIFICATE ENTRY----------------- CA: TLS-ABCD Certificate: Data: Version: 3 (0x2) Serial Number: 4125 (0x101d) Signature Algorithm: sha256WithRSAEncryption Issuer: C=US, ST=CA, L=SJ, O=ROOTCA-CC, OU=SQA, CN=ROOTCA-CC/emailAddress=user@arris.com Validity Not Before: Nov 7 02:24:18 2017 GMT Not After : Nov 17 02:24:18 2018 GMT Subject: CN=DUTFIPSCC, ST=CA, C=US/emailAddress=user@arris.com, O=DUTFIPSCC, OU=SQA device# device# show pki certificates trustpoint ----------------PKI TRUSTPOINT CERTIFICATE ENTRY----------------- CA: TLS-ABCD Certificate: Data: Version: 3 (0x2) Serial Number: bd:fa:4f:da:bd:89:4a:5d Signature Algorithm: sha256WithRSAEncryption Issuer: C=US, ST=CA, L=SJ, O=ROOTCA-CC, OU=SQA, CN=ROOTCA-CC/emailAddress=user@arris.com Validity Not Before: Nov 7 02:10:00 2017 GMT Not After : Nov 7 02:10:00 2022 GMT Subject: C=US, ST=CA, L=SJ, O=ROOTCA-CC, OU=SQA, CN=ROOTCA-CC/emailAddress=user@arris.com device# - Validate the certificates using the following command.
The following example provides the syntax for validating the imported certificates.The following example successfully validates certificates imported from the trustpoint abcd.
The following example imports certificates for the configured trustpoint abcd, authenticates the trustpoint, and validates imported certificates.
device# configure terminal device(config)# crypto key generate rsa device(config)# pki import key rsa rsakey pem url flash: dut.key.pem device(config)# pki import abcd pem url flash: rootca.pem device(config)# pki import abcd pem url flash: localcert.pem device(config)# pki trustpoint abcd device(config-pki-trustpoint-abcd)# ocsp http post device(config-pki-trustpoint-abcd)# revocation-check ocsp device(config-pki-trustpoint-abcd)# ocsp-url http://10.21.40.39:2560 device(config-pki-trustpoint-abcd)# fingerprint 3C:EA:EC:E6:F1:DD:3B:86:65:DE:58:F4:A2:75:D8:63:6D:23:68:40 device(config-pki-trustpoint-abcd)# exit device(config)# pki authenticate abcd device(config)# pki cert-validate abcd PKI: Successfully validated the local certificate for trustpoint: abcd