3-61
Initial Setup of the ProCurve NAC 800
Digital Certificates
5.
Enter this command:
For example:
ProCurve NAC 800:/usr/local/nac/keystore:# keytool
-import -alias mynac.procurve.com -trustcacerts -file mynac.cer -keystore
compliance.keystore
6.
When prompted, enter the password for the keystore (
changeit
).
Restart the HTTPS Server
The NAC 800 begins to use the new certificate the next time the HTTPS server
starts. Enter the following command from the root to restart the server:
Install a New Self-Signed Certificate for HTTPS
The NAC 800 can identify itself to users that access its HTTPS server with a
self-signed certificate (instead of with a CA-signed certificate). A self-signed
certificate is easier to install because it does not require you to purchase a
certificate from a third-party vendor nor have your own CA. On the other hand,
a self-signed certificate is less trusted; users might have to choose to trust it
when they access the NAC 800’s Web browser interface.
You must complete these tasks to create and install a self-signed certificate:
1.
Generate the self-signed certificate and keypair in the
compliance.key-
store
.
2.
Export the self-signed certificate to a file.
3.
Install the self-signed certificate as a trusted CA root certificate in the Java
cacerts
keystore.
Syntax:
keytool -import -alias <
keyname
> -trustcacerts -file <
cert_filename
>
-keystore compliance.keystore
Replace
<
keyname
>
with the name you specified in step 3 of
“Generate a Key” on page 3-52. Replace
<
cert_filename
>
with
the filename that you gave to the certificate in step 1-d.
This command adds the signed certificate to the keystore in
the usr/local/nac/keystore directory.
Syntax:
service [nac-ms | nac-es] restart
Restarts the nac-ms or nac-es services, including the HTTPS
server. On an MS, select
nac-ms
. On an ES, select
nac-es
. On a
CS, restart both services.
Summary of Contents for 800
Page 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Page 2: ......
Page 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Page 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Page 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Page 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Page 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Page 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Page 380: ...A 26 Appendix A Glossary ...
Page 394: ...B 14 Appendix B Linux Commands Service Commands ...
Page 405: ......