Use the
password
and
password-alias
properties in environments that require
password-protected files. Before using the
password-alias
property, use the
password-map
command to 3DES-encrypt the private key password (
plaintext
) and
associate an alias with the encrypted password. An attempt to reference an
encrypted password that is not in the password map results in command failure.
v
In environments that use unencrypted passwords, the value of the
password
property is used to open and read the key file.
v
In environments that use encrypted passwords, the password map file is queried
for the value of the
password-alias
property, and its associated encrypted
password is identified. The encrypted password, in turn, is 3DES-decrypted
using the locally generated host key to yield the plaintext password that is used
to open and read the key file.
Related Commands
password-map
Examples
v
Generates a private key and CSR for the specified server. Default conditions
apply as follows:
– The private key (1024-bits in length) is saved as
cert:sample-privkey.pem
.
– The CSR is saved as
temporary:sample.csr
.
– The private key file is not password protected
# keygen C au L "South Melbourne" ST Victoria
O "DataPower Australia, Ltd." OU "Customer
Support" CN www.bob.datapower.com.au
#
v
Generates a private key and CSR for the specified server with the following
options.
– The private key (2048-bits in length) is saved as
cert:bob-privkey.pem
.
– The CSR is saved as
temporary:bob.csr
.
– The private key file is password protected with the plaintext password
didgeridoo
.
# keygen C au L "South
Melbourne" ST Victoria
O "DataPower Australia, Ltd." OU "Customer
Support" CN www.bob.datapower.com.au rsa 2048 out bob password
didgeridoo
#
v
Creates a new password map and generates a host key to 3DES-encrypt the
plaintext password
didgeridoo
, and associates the alias
WaltzingMatilda
with
the encrypted password.
Generates a private key and CSR for the specified server with the following
options.
– The private key (2048 bits in length) is saved as
cert:bob-privkey.pem
.
– The CSR is saved as
temporary:bob.csr
.
– The private key file is password protected with the encrypted password
didgeridoo
.
# password-map
Please enter alias-name and plaintext password pairs
- Leading and trailing white space is removed
- Enter a blank alias name to finish
Alias-name: WaltzingMatilda
Plaintext password: didgeridoo
Chapter 11. Crypto configuration mode
229
Summary of Contents for WebSphere XS40
Page 1: ...WebSphere DataPower XML Security Gateway XS40 Command Reference Version 3 7 2 ...
Page 2: ......
Page 3: ...WebSphere DataPower XML Security Gateway XS40 Command Reference Version 3 7 2 ...
Page 44: ...18 Command Reference ...
Page 194: ...168 Command Reference ...
Page 198: ...172 Command Reference ...
Page 206: ...180 Command Reference ...
Page 210: ...184 Command Reference ...
Page 222: ...196 Command Reference ...
Page 232: ...206 Command Reference ...
Page 238: ...212 Command Reference ...
Page 268: ...242 Command Reference ...
Page 272: ...246 Command Reference ...
Page 276: ...250 Command Reference ...
Page 288: ...262 Command Reference ...
Page 292: ...266 Command Reference ...
Page 298: ...272 Command Reference ...
Page 320: ...294 Command Reference ...
Page 322: ...296 Command Reference ...
Page 340: ...314 Command Reference ...
Page 344: ...318 Command Reference ...
Page 352: ...326 Command Reference ...
Page 360: ...334 Command Reference ...
Page 368: ...342 Command Reference ...
Page 376: ...350 Command Reference ...
Page 386: ...360 Command Reference ...
Page 392: ...366 Command Reference ...
Page 396: ...370 Command Reference ...
Page 402: ...376 Command Reference ...
Page 404: ...378 Command Reference ...
Page 408: ...382 Command Reference ...
Page 446: ...420 Command Reference ...
Page 450: ...424 Command Reference ...
Page 456: ...430 Command Reference ...
Page 520: ...494 Command Reference ...
Page 536: ...510 Command Reference ...
Page 550: ...524 Command Reference ...
Page 584: ...558 Command Reference ...
Page 600: ...574 Command Reference ...
Page 605: ... timeout 500 Chapter 63 RADIUS configuration mode 579 ...
Page 606: ...580 Command Reference ...
Page 650: ...624 Command Reference ...
Page 668: ...642 Command Reference ...
Page 704: ...678 Command Reference ...
Page 714: ...688 Command Reference ...
Page 726: ...700 Command Reference ...
Page 734: ...708 Command Reference ...
Page 752: ...726 Command Reference ...
Page 756: ...730 Command Reference ...
Page 804: ...778 Command Reference ...
Page 880: ...854 Command Reference ...
Page 892: ...866 Command Reference ...
Page 912: ...886 Command Reference ...
Page 918: ...892 Command Reference ...
Page 940: ...914 Command Reference ...
Page 946: ...920 Command Reference ...
Page 974: ...948 Command Reference ...
Page 1004: ...978 Command Reference ...
Page 1030: ...1004 Command Reference ...
Page 1032: ...1006 Command Reference ...
Page 1065: ......
Page 1066: ... Printed in USA ...