Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.


Panel

In this section:

Table of Contents
maxLevel3



The Public Key Infrastructure (PKI) provides a common set of infrastructure features supporting public key and certificate-based authentication based on the RSA public/private key pairs and X.509 digital certificates.

Multiexcerpt
MultiExcerptNameCertificate Types

Certificate Types

Local-Internal Certificates

In previous 

Spacevars
0product
versions, the RSA key pairs and Certificate Signing Request (CSR) for
Spacevars
0product
platforms were generated on an external workstation. The CSR was then submitted to a Certificate Authority, and the resulting certificate was received back from the CA, copied onto the workstation, and combined with the private key in a PKCS#12 file which was used to install the key pair and certificate onto the
Spacevars
0product
.

The 

Spacevars
0product
application can now generate and install RSA key pairs and generate Certificate Signing Request (CSR) on the 
Spacevars
0product
system itself. The certificate request is sent to a CA, and the issued certificate is then installed on the
Spacevars
0product
. The local-internal certificate option simplifies the certificates and keys managing process and also provides more security since the private key never leaves the
Spacevars
0product
. For steps to configure local-internal certificates, see Generating PKI Certificates.

Certificate file format: PKCS12PEM

Local Certificates

Local certificates are credentials belonging to the local system itself, which it presents to peers in order to prove its identity. You must download local certificate files to the system before installing the certificates.

Certificate file format: PEM PKCS12

Remote Certificates

Remote certificates are credentials belonging to Certificate Authorities (CA). The copies of these certificates are installed in the 

Spacevars
0product
because they are part of a chain of certificates the local system will present to peers, or because the corresponding CAs are trust anchors for the local system. Certificates belonging to non-CA remote systems should also be installed as trust anchors in this manner.

The Certificate Authority (CA) certificates and trusted remote certificates contain public key certificates; they do not contain the private keys. The CA certificates and remote certificates are Distinguished Encoding Rules (DER) format files; a method for encoding a data object (such as an X.509 certificate) which uses a digital signature to bind together a public key with an identity.

Certificate file format: DER


Include Page
Max_Nbr_TLS_Certs
Max_Nbr_TLS_Certs

Command Syntax

Set Command Syntax

Code Block
languagenone
% set system security pki certificate <certificate name>
	fileName <1-255 characters>
	passPhrase <pass phrase>
	state <disabled | enabled>
	type <local | local-internal | remote>

% show system security pki
 
% delete system security pki

Request Command Syntax

Multiexcerpt include
MultiExcerptNamesecurity_syntax
nopaneltrue
PageWithExcerptRequest System - CLI

Command Parameters

Set Parameters

Caption
0Table
1set system security Parameters


Parameter

Description

certificate

<certificate name> – The collection of certificates configured on the SBC.

fileName

<filename> – Certificate content filename in the format:

  • Local-Internal: PKCS12PEM
  • Local: PEM PKCS12
  • Remote: DER

passPhrase

Specifies the pass-phrase to decrypt RSA private key in PKCS12 file.

Note: The passPhrase is limited to 23 characters.

state

Administration state of this certificate. Options are:

  • disabled – Prohibits the PKI certificate from being used by the 
    Spacevars
    0product
    for authenticating remote peers (when this is a remote certificate) OR presenting its own identity (in case of a local or local-internal certificate).
  • enabled – Certificate can be used by 
    Spacevars
    0product
    for authentication purposes.
Note

The certificate must first be installed on the 

Spacevars
0product
before enabling it.


type

Specifies the certificate type – CA (remote) certificate or local certificate. Options are:

  • local Certificate belongs to (has as its subject) the local system itself; the key pair and CSR were generated elsewhere.
  • local-internal Certificate belongs to (has as its subject) the local system itself; the key pair and CSR were generated on this machine.
  • remote Certificate belongs to (has as its subject) a remote entity such as a  CA or peer device.

Request Parameters

Multiexcerpt include
MultiExcerptNamesecurity_parameters
nopaneltrue
PageWithExcerptRequest System - CLI

Command Example

To display security management configuration:

Code Block
languagenone
% show system security pki certificate
certificate testSBCCert {
    state 		enabled;
	fileName	sonuscert.pem
    type  local-internal;
}
certificate defaultSBCCert {
    state      enabled;
    fileName   sonuscert.p12;
    passPhrase $3$KFfiuJ0Lifk=;
    type       local;
}

Pagebreak