crypto import

Imports the Identity Certificate for security configuration.

Syntax

crypto import { ldapca | radiusca | syslogca | gnmiclientca |httpsclientca } directory dir-name file file-name host host-address protocol { FTP | SCP } source-ip source-ip user user-name password password
no crypto import { ldapca | radiusca | syslogca |gnmiclientca |httpsclientca }

Parameters

ldapca | radiusca | syslogca | gnmiclientca | httpsclientca
Defines the type of certificate to import. Select from ldapca, radiusca, syslogca, gnmiclientca, or httpsclientca.
directory dir-name
Defines the remote directory where the certificate file resides.
file file-name
Defines the name of the certification file.
host host-address
Defines the host name or IP address of the remote certificate server.
protocol { FTP | SCP }
Specifies the use of either FTP or SCP protocol for accessing the certificate file.
source-ip source-ip
(SCP only) Specifies the source IP address to use in the header.
user user-name
Defines user name for the remote certificate server.
password password
Defines the password for the user name for the remote certificate server.
Note

Note

When the password is not provided in the CLI command, the user will be prompted for it when the CLI is executed.
Note

Note

gNMI Client CA is needed for mutual TLS communication. For server based authentication, gNMI Client CA is optional.

Modes

Privileged EXEC mode

Usage Guidelines

Use the no form of the command to remove the Identity Certificate.

Examples

This example imports a RADIUS certificate over SCP.

device# crypto import radiusca t1 certificate protocol SCP host 10.10.10.10 
                    user fvt directory /users/crypto file cacert.pem password ****

Example

This example imports a gNMI client CA certificate over SCP.

device# crypto import gnmiclientca directory  /home/kokila/ocsp_cert_116/certs/ file ca.cert.pem host 10.23.20.116 protocol SCP user kokila password ***

Example

This example deletes gNMI client CA certificate.

device# no crypto import gnmiclientca

Example

This example deletes RADIUS server CA certificate.
device # no crypto import radiusca