Change the certificate used by a Cisco 3850

I have a new L3 3850 switch. He had a self-signed certificate installed when I first started the switch. The certificate is displayed either 512 or 1024 in length. I would like to create a key of 2048 in length. Can I issue the command generated rsa encryption key and specify the length of 2048 and I get a new cert. I can't just understand hw to make the new cert as the active cert.

When he started it first, here is the configuration of the switch section:

Crypto pki trustpoint TP-self-signed-127070658

enrollment selfsigned

name of the object cn = IOS - Self - signed - certificate - 127070658

revocation checking no

rsakeypair TP-self-signed-127070658

!

!

TP-self-signed-127070658 crypto pki certificate chain

certificate self-signed 01 nvram:IOS - Self-Sig #1.cer

When I create new cert and validate them with the copy running-config startup-config and then recharge, it will show that the new cert is stored in NVRAM:private - config, but it does not show the cert when I cd in NVRAM: and issue the dir command. What is the right order to get the new cert to use.

Here are the results of the dir command:

2049 rw-1897 startup-config

2050-3821 private-config

2051 rw-1897 base-config

1 0 rf_cold_starts

2 cpu_trap.eci of - rw - 1079

4 rw-1072 cpu_threshold_trap.eci

6 - rw - 886 memory_trap.eci

7 - rw - 858 rf_trap.eci

8 rw-3123 wireless_trap.eci

11 - rw - 270 ma_trap_keyword

12-86 - persistent data

14 - rw - 578 IOS-Self-Sig #1.cer

-rw-0 15 ifIndex-table

William Coats

I was wondering how to do it myself, so I took him as a small project on our laboratory 3650. The documentation leaves to be desired, but I finally thought to it.

1 generate a 2048 bit rsa key pair:

seclab-3650 (config) #crypto generate keys rsa 2048 2048-bit-key module label

2. create a trustpoint specifying registration self-signed and tell the TP to use this key pair

seclab-3650 (config) #cry pki trustpoint 2048-bit-TP

seclab-3650(ca-trustpoint) #enrollment selfsigned

seclab-3650(ca-trustpoint) #usage - server ssl

seclab-3650(ca-trustpoint) #on nvram:

seclab-3650(ca-trustpoint) #rsakeypair 2048-bit-key

seclab-3650(ca-trustpoint) #exit

3 register the trustpoint - at this point the switch will generate the 2048-bit certificate.

seclab-3650 (config) #crypto pki enroll 2048-bit-TP

% Include the serial number of the router in the name of the topic? [Yes/No]: Yes

% Include an IP address in the name of the topic? [None]:

Generate a self signed certificate router? [Yes/No]: Yes

Router self-signed certificate created successfully

seclab-3650 (config) #.

4. tell your ip http secure server to use this trustpoint

seclab-3650 (config) #ip http secure-trustpoint 2048-bit-TP

Once I did this, I can go to the switch via https and see the key of 2048 bits being used in the self-signed certificate. Click on the image below to enlarge:

Tags: Cisco Network

Similar Questions

  • I changed my password of gmail e-mail. How can I change the password used by Thunderbird to connect to gmail.

    I changed the password used to access my gmail account. Thunderbird still uses the old password to access the account. How can I change the password that is using Thunderbird. The last time this happened I ended up creating a new account to Thunderbird for gmail. Create the new Thunderbird account at least let me enter the new password. I don't really want to have three accounts of Thunderbird for the same gmail account.

    Please do not respond with suggestions on using password manager. I do not use it and do not want to start. I looked, and none of my Thunderbird passwords are displayed here. All I want to do is change the password in Thunderbird. If Thunderbird does not have a feature that allows you to change passwords, should be added.

    The link posted by Christ1 gives WRONG directions. In Thunderbird 24.4.0, is:
    Tools, Options, security, passwords, saved passwords

    Admittedly, in fact, you want that he SHOWS you the passwords, and then you can delete them.
    Once fact you check for mail, it will tell you, it didn't, and then you have the option to enter a new password.
    MUCH too complicated. Time to put the password and the ability to change, in the e-mail account options.

  • How will I know if my Airport Extreme has the latest firmware?  And (not related) how to change the password used to connect to my network?

    I think I bought the latest version of Airport Extreme.  It is the unit which is rectangular, is about 6 to 7 w., etc.  I have some basic questions that I do not understand:

    1. How will I know if I have the latest firmware for this device?  I read a few posts that make it sound as if it was just automatically updates.  Is this true?

    2. can someone tell me how to change the password used to connect to my wireless network?

    Thank you very much!

    Chris

    If a firmware update is available, AirPort Extreme flashes orange.

    The most up-to-date version of the firmware is 7.7.3.

    You can see what version you currently have the following on your Mac...

    Open Finder > Applications > utilities > AirPort Utility

    Click on the image of the AirPort Extreme

    Look for the Version

    If the new firmware was available, you will see a button update here

    To change the wireless network password...

    Click on edit in the window smaller than you watched just to check the firmware version

    Click on the Wireless tab at the top of the next window

    Go back / change the wireless password and enter a new password

    Do the same thing to check

    Click Update at the bottom right of the window and give the airport a minute full for restart

  • Change the headings used in Command Center?

    I was wondering if there is a way to change the elements used in the command center? For example, to replace the calendar with something else.

    Thank you

    There is currently no way to change the applications that are launched via app Droid Turbo command center. The clock, batteries and the Accu Weather apps are the main applications, and calendar via the "Pop out" are the only ones available.

    There are other applications on the game you might like better as the "Rings Digital Weather Clock" you might find more functional for a particular use from you.

    I hope this helps!

  • At the point of the map, how to change the font used

    Hello

    I want to change the font used in the bubble in Mappoint. I don't talk about boxing of text or the text size, I just want to change the police and use "Microsoft sans Serif".

    Is this possible?

    How to do?

    I used Windows 7,

    Best regards

    You can ask in the following forum because they are more likely to have relevant experts:

    Highway, streets and Trips, MapPoint .

  • My Windows XP pro would not let me change the option 'Use the home screen', so I removed a vital .dll file. I can't start Windows now!

    My Windows XP pro would not let me change the "Use welcome screen" option under: user accounts/change the way users connect or power off.

    He gave a message to the effect (I forgot to write it!) "a recently installed program does not change this setting. Search in the file named "RtlGina2.dll for a clue. So as silly as I can be, I did a search, finds the file RtlGina2.dll in the Windows/System32 folder and cut and paste on my desk. My thought was to isolate this file to see if it will address the problem of not being able to change the option use Windows screen.

    Now, I can't run Windows! It gives a message that this file RtlGina2.dll is not found! Specifically, it says, User Interface failure. The UI for logon RtlGina2.dll DLL failed to load. Contact your system administrator to replace the DLL or restore the original dll.

    How can I replace the dll if I can't even get started? Help, please! I know just enough to get me in trouble I see.

    WyoPathfinder,
    Are you able to boot mode safe mode with command prompt?  If Yes, then you can search for the file "dir /s /a RtlGina2.dll" lists the location where you moved to.  Then you can just copy (path\filename) c:\Windows/System32\(filename)

    If you do not work in safe mode, then you can boot from a XP disc and go into the recovery console and do the same thing.

    Hope that helps. QQ learn manage!

  • How to change the rendering used for video playback in Windows Media Center Version 6 engine

    I usually use other media players, but I would like to first of all using Windows Media Center. However for the moment video playback is not good because of the weird colors (everything is displayed in black and Red instead of normal colors). When you use other media players, I use the Haali rendering engine which gives good results for video playback.

    Can you tell me how to change the rendering used by Windows Media Center?

    Also, I noticed the same weird color effect in Windows Media Player 11.

    Hi Woobee,

    1. What is the brand and model of the computer?

    2. what graphics card use on the computer?

    If you are using an Nvidia graphics card on the computer, in the Nvidia Desktop Manager, you will find an option for saturation to ensure it is set to 100%.

    And if you are any other graphics card on the computer and search for a similar option for saturation.

    If the previous step fails in Windows media player, so be sure that the hue and Saturation are defined by default.

    1. click on the arrow on the tabplaying , point to enhancements, and then clickcolor picker.

    2. do one of the following:

    1. to return to the default color, click thereset link.

    Also, make sure that the video settings are set by default.

    1. start the playback of a file.

    2. click on the arrow on the tabplaying , point to improvements, and then clickvideo settings.

    3. click onreset.

    Check also in Windows Media Center if the

    1. on theStart screen, go to tasks, click settings, clickgeneral, then Visual and sound effects.

    2. undercolors ensure that Windows media center standard is enabled.

    Turn off Visual and sound effects in Windows Media Center

    http://Windows.Microsoft.com/en-us/Windows-Vista/turn-off-Visual-and-sound-effects-in-Windows-Media-Center

    I hope this helps!

    Halima S - Microsoft technical support.

    Visit ourMicrosoft answers feedback Forum and let us know what you think.

  • I can't change the location using activation please

    I can't change the surprise using activation please

    Hello

    Sorry for the inconvenience caused.

    I suggest refer you to the link below on how to enable Windows 8.

    http://Windows.Microsoft.com/en-us/Windows-8/why-activate-Windows

    I hope this helps.

  • How to find the certificate used to sign app?

    There is a site that uses DBsign UWS to validate personal certificates on a smart card.  I found myself breaking this feature by moving the default Java truststore so I could create a new one with a few roots/split AC that I trust (I have no desire to let apps signed by China, Russia, Turkey and countries spelled with heiroglyphs).  Now, my browser thinks that the UWS is self-signed and rfuses to run it.  I need to find the certificate used to sign this app to see what cert (s) sign, so I can add them to the truststore.  How can I find that?

    To answer my own question:

    jarsigner - verify - verbose - CERT DBsignUWS.jar

  • Change the vmnic used by the service console

    Can someone help me change the vmic used by the concole service, when I write the command excfg, I get the message:

    excfg-vswitch - L vminc0 vSwitch0 "segmentation fault".

    Thanks to y using the year.

    AFAIK vmnic0 is assigned by default to vSwitch0.

    First, try it canceled with: esxcfg-vswitch - U vmnic0 vSwitch0

    I use the procedure below to delete vSwitch0 and create a service named TSV - cos console switch.

    esxcfg-vswif vswif0 d

    esxcfg-vswitch - del - pg = "Service Console" vSwitch0

    esxcfg-vswitch vSwitch0 d

    esxcfg-vswitch - TSV - cos

    esxcfg-vswitch - L vmnic0 TSV - cos

    esxcfg-vswitch-add-pg = "Service Console" TSV - cos

    esxcfg-vswif - a vswif0 Pei "Service Console"-i < ESXHOSTIP > - < ESXHOSTSUBNETMASK > n

    Arnim - van Lieshout

    -

  • Urgent: Not able to change the certificate in DPS app Builder

    Hello

    We are about to publish an application with the individual edition license. We did a version and then the customer discovered that the certificate must be changed.

    However, when we try to create the application, then fill in the information, there is no option to change the certificate - only configuration profiles.

    We tried searching high and low and you have not found a solution. In addition, the button Delete is grey is not possible to erase and start over.

    How can we change the certificate? The attached screen shows the screen after uploaded Prov. profiles, but there are certificate is checked while the CERT has not yet been added.

    BR,

    Mikkel

    Skærmbillede 2013-02-05 kl. 14.01.12.png

    Mikkel, you can only choose mobile configuration files. Once you click on create app it will generate the application.

    Once you click on the Finish button. It will give you two files developer.ipa and distribution.zip.

    When you download developer.ipa it will give you a different dialog box that ask you to select the developer & partner and developer .p12 certificate mobile service password file.

    Then click on the sign and download it. See attached screenshot:

  • change the port used by apex 4.0

    Hello

    How can I change the port used by apex? For example, instead of 8080 I want to use 8081

    Thank you

    If you use OC4J, or any other application server, but you do not use the EPG you must reset the EPG

    exec dbms_xdb.sethttpport( 0 );
    
  • Renew the certificate of identity on Cisco ASA 5505, do I have to renew all user certificates?

    n00b questions.

    I have to renew my SSL certificate of identity soon on my Cisco ASA 5505.  I'll have to renew all my certificates for client on their devices, so they can establish a vpn tunnel?

    Hi dsartoros,

    If you encounter a self signed (generated locally) identity certificate renewed, then you will need to download this certificate on the clients so that they can connect without getting "untrusted server certificate error".

    If you renew a certificate issued by a 3rd party CA (sending of CSR to CA) and certificate, then you will not need to make any changes on the client as they already trust the certification authority that issues the certificate first root.

    Kind regards
    Dinesh Moudgil

    PS Please rate helpful messages.

  • How to change the certificate watermark in Adobe Reader

    I need to change the watermark of signature of a document using a certificate, the default seal adobe logo.  I followed the instructions on the following link, which I pulled the relevant article of like the image below to save the time potential helpers. -> 4 appearances of personal - Signature guide digital for HER signature

    Watermark.jpg

    Everything was fine until they hit the location of the file in which the file SignatureLogo.pdf.  There is no such location of the file.  Or something like that.  I guess it's a difference between Acrobat and Reader.  Where I put this file for Adobe Reader?  I've already rooted through all files in C:-> Program Files-> Adobe-> Player 11.0 and go home empty-handed.  There is no security file.  I tried to create a folder called security in Reader 11.0 and place the file inside, it works no more.

    Search turned up nothing else than to unanswered questions.  I hope I have provided enough context information that mine will not the same thing, as a local jurisdiction requires that said watermark to change, and there are drawings for a project that cannot be made until this.

    The change can be done using only the free player.

  • How to change the fonts used to display the list of emails on the homepage?

    Looking at my Inbox or other e-mail folder, the font used to display the list of emails in folders - gives me a headache.

    How can I change this font? Is there an add-on? Something in their profile?

    Ideally, I would like to change the background color of white also. (Perhaps the color on this page where I ask the question. "It's easy to read, the font and the color!)

    I've been a programmer in a past life, so I'm tech abreast. I am new to use Thunderbird (I used FF for several years.)

    Thank you!!

    Yes, to change the font, you can use this addon:

    Also, try to use themes:

Maybe you are looking for