
associated with
Certificate
Use the drop down list to select the name of a certificate that you would like
to associate the SNI with.
7. Click on Commit to save the SNI where it will be displayed on the accordion list on the SNI tab.
8. Add additional SNI objects to certificates as necessary.There is no maximum limit to the number of SNI
objects that can be associated with each certificate. If you would like to remove an SNI, select the
accordion tab on the SNI screen and click on the button.
Server Name Indication Using theCLI
Proceed with the following to configured SNI certificates on an HTTPS cluster using the CLI:
1. Configure an HTTPS cluster on Equalizer. Use the CLI syntax described in "Cluster and Match Rule
Commands" on page 146.
2. Add a default certificate to the cluster if one has not been added previously. Use the CLI syntax described
in "Cluster and Match Rule Commands" on page 146.
3. Use the following CLI syntax to upload other certificates and the associated key files to Equalizer's file
store.
eqcli > cert certname
eqcli cert-certname> certfile {edit|url}
Do the same for the associated key files:
eqcli > cert certname
eqcli cert-certname> keyfile {edit|url}
4. Add an SNI object by entering the following in the HTTPS cluster context. The SNI name can be up to 47
ASCII characters and can include period (.), dash (-), and underscore (_).
eqcli cl-HTTPS*> sni testsni
eqcli cl-HTTPS*-sni-tes*>
5. Now associate certificates with the new SNI by entering the following in the SNI context:
eqcli cl-NEW* > sni testsni
eqcli cl-NEW*-sni-tes*> certificate snicertificate1
eqcli cl-NEW*-sni-tes*>
Copyright © 2013 Coyote Point Systems. A subsidiary of Fortinet, Inc.
All Rights Reserved.
301
Equalizer Administration Guide
Comentarios a estos manuales