HP 3350 - Cisco NAC Appliance Spezifikationen Seite 579

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 681
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 578
14-16
Cisco NAC Appliance - Clean Access Manager Configuration Guide
OL-28003-01
Chapter 14 Administering the CAM
Manage CAM SSL Certificates
If you try to upload a root/intermediate CA certificate for the CAM that is already in the list, you may
see an error message reading “This intermediate CA is not necessary.” In this case, you must delete the
uploaded Root/Intermediate CA in order to remove any duplicate files.
Export Certificate and/or Private Key
Note You cannot export the Private Key for a FIPS 140-2 compliant CAM. You can only export certificates.
To backup your certificate and/or Private Key in case of system failure or other loss, you can export your
certificate and/or Private Key information and save a copy on your local machine. This practice also
helps you manage certificate/Private Key information for a CAM HA-Pair. By simply exporting the
certificate information from the HA-Primary CAM and importing it on the HA-Secondary CAM, you are
able to push an exact duplicate of the certificate info required for CAM/CAS communication to the
standby CAM.
Step 1 Go to Administration > CCA Manager > SSL > X509 Certificate (Figure 14-7).
Step 2 To export existing certificate/Private Key information:
a. Select one or more certificates and/or the Private Key displayed in the certificates list by clicking on
their respective left hand checkboxes.
b. Click Export and specify a location on your local machine where you want to save the resulting file.
Manage Trusted Certificate Authorities
You can locate, remove, and import/export Trusted CAs for the CAM database using the Administration
> CCA Manager > SSL > Trusted Certificate Authorities CAM web console page. To keep your
collection of trusted certificate authorities easily manageable, Cisco recommends keeping only trusted
certificate authority information critical to Cisco NAC Appliance operations in the CAM trust store.
You can also use this function to import Root and Intermediate Certificate Authorities.
Note You must upload the PEM-encoded CA-signed certificate on both the CAM and CASs in your Cisco
NAC Appliance network.
If there are multiple Intermediate CA files, you can also copy and paste them into a single Intermediate
CA PEM-encoded file for upload to the CAM using the procedure in Manage Signed Certificate/Private
Key, page 14-14.
Seitenansicht 578
1 2 ... 574 575 576 577 578 579 580 581 582 583 584 ... 680 681

Kommentare zu diesen Handbüchern

Keine Kommentare