Cisco Cisco Web Security Appliance S170 사용자 가이드

다운로드
페이지 734
 
5-14
Cisco IronPort AsyncOS 7.5.7 for Web User Guide
Chapter 5      FIPS Management
Using the fipsconfig CLI Command
Backing up Certificates and Keys
To back up the certificates and keys the HSM card manages:
Step 1
From the FIPS management console, click Edit Settings in the Key Management section.
The Edit Key Management Settings page displays.
Step 2
Scroll down to the Backup Certificates and Keys section, and choose the file name to use for the XML 
file that will contain the encrypted certificate and key pairs. You can define your own file name or 
AsyncOS for Web can choose one for you.
Step 3
Click Backup.
Step 4
Choose to save the file, and click OK.
Step 5
Navigate to the directory on the local machine to where you want to save the XML file, and click Save.
Restoring Certificates and Keys
When you back up the certificates and keys the HSM card manages, the keys are encrypted. Because the 
keys are encrypted, they can only be restored on a different FIPS-compliant Web Security appliance if 
the master key on the other appliance is the same as the one from which the certificates and keys were 
backed up. Note that when the HSM card gets initialized, its master key changes. For more information 
on copying the master key between appliances, see 
To restore a certificate and key pair stored in an XML file:
Step 1
From the FIPS management console, click Edit Settings in the Key Management section.
The Edit Key Management Settings page displays.
Step 2
Scroll down to the Restore Certificates and Keys section, and click Browse.
Step 3
Navigate to the directory on the local machine where the XML file resides, and click Open.
Step 4
Click the check boxes for the certificate and key pairs you want to restore. 
Step 5
Click Restore.
Using the fipsconfig CLI Command
AsyncOS for Web includes the 
fipsconfig
 CLI command to perform the following tasks:
  •
Initialize the HSM card.
  •
Read the HSM card status.
  •
Configure the certificate and key to access the appliance web interface.
  •
Configure multiple HSM cards to use the same master key.
When you enter 
fipsconfig
 at the command line, the CLI prompts you to enter the FIPS Officer 
password. For more information, see 
.