admin commands

The admin commands are used to perform administrative functions, such as displaying configuration that is not subject to AAA, manually saving the configuration, clearing user sessions, and rebooting the system.

admin 
clear 
security 
lockout 
all 
user named-item
password-history 
all 
user named-item
disconnect 
address (ipv4-address-no-zone | ipv6-address-no-zone)
op-table-bypass boolean
session-id number
session-type keyword
username named-item
ipsec 
show 
key 
gateway named-item
ip-tunnel interface-name
ipsec-tunnel named-item
peer-tunnel-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
peer-tunnel-port number
type keyword
nat 
save-deterministic-script 
reboot 
[card] keyword
hold 
now 
redundancy 
force-switchover 
now 
synchronize 
boot-environment 
certificate 
configuration 
save 
bof 
cleartext 
configure 
debug 
[url] string
set 
time 
[system-time] date-and-time
show 
configuration 
bof 
booted 
cflash-id cflash-id
[cli-path] cli-path-type
configure 
debug 
depth number
detail 
flat 
full-context 
inheritance 
intended 
json 
running 
units 
xml 
support-mode 
disable 
kernel 
password encrypted-leaf
shell 
password encrypted-leaf
system 
license 
activate 
[file-url] string
now 
clear 
now 
validate 
[file-url] string
management-interface 
commit 
confirmed 
accept 
cancel 
operations 
delete-operation 
[delete-id] number
op-table-bypass boolean
stop-operation 
op-table-bypass boolean
[stop-id] number
security 
hash-control 
custom-hash 
algorithm keyword
key string
remove-custom-hash 
os-security 
anti-theft 
activate 
card reference
force 
password string
deactivate 
card reference
force 
password string
unlock 
password string
remove-password 
force 
password string
set-password 
current-password anti-theft-password-cleartext
force 
new-password anti-theft-password-cleartext
pki 
clear-ocsp-cache 
[entry-id] number
cmpv2 
cert-request 
ca-profile reference
current-certificate pki-file-name
current-key pki-file-name
domain-name string
hash-algorithm keyword
ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
new-key pki-file-name
save-as cflash-url
subject-dn string
clear-request 
ca-profile reference
initial-registration 
ca-profile reference
certificate pki-file-name
domain-name string
hash-algorithm keyword
ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
key-to-certify pki-file-name
password string
protection-key pki-file-name
reference string
save-as cflash-url
send-chain 
subject-dn string
with-ca reference
key-update 
ca-profile reference
hash-algorithm keyword
new-key pki-file-name
old-certificate pki-file-name
old-key pki-file-name
save-as cflash-url
poll 
ca-profile reference
convert-file 
force 
format keyword
[input-file] pki-file-name
[output-file] pki-file-name
crl-update 
ca-profile reference
est 
ca-certificates 
est-profile string
force 
output-url cflash-url
enroll 
domain-name string
est-profile string
force 
hash-algorithm keyword
ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
key cflash-url
output-file pki-file-name
subject-dn string
validate-certificate-chain 
renew 
certificate cflash-url
est-profile string
force 
hash-algorithm keyword
key cflash-url
output-file pki-file-name
validate-certificate-chain 
export 
format keyword
input-file pki-file-name
key-file pki-file-name
output-url cflash-url
password string
type keyword
generate-csr 
domain-name string
hash-algorithm keyword
ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
key-url cflash-url
output-url cflash-url
subject-dn string
use-printable 
generate-keypair 
dsa-key-size number
ecdsa-curve keyword
rsa-key-size number
[save-path] cflash-url
import 
format keyword
input-url cflash-url
output-file pki-file-name
password string
type keyword
validate-certificate-chain 
reload 
application keyword
certificate pki-file-name
key pki-file-name
show 
file-content 
[file-path] cflash-url
format keyword
password string
type keyword
update-certificate 
certificate reference
secure-boot 
activate 
card reference
confirmation-code string-not-all-spaces
serial-number string-not-all-spaces
revoke-key 
card reference
confirmation-code string-not-all-spaces
serial-number string-not-all-spaces
update-key 
card reference
confirmation-code string-not-all-spaces
serial-number string-not-all-spaces
software-image cflash-and-url
validate 
software-image cflash-and-url
system-password 
admin-password 
telemetry 
grpc 
cancel 
all 
subscription-id number
tech-support 
[url] url

admin command descriptions

admin

Synopsis Enter the administrative context for system operations
Contextadmin
Treeadmin
Introduced25.3.R2

Platforms

7705 SAR Gen 2

clear

Synopsis Enter the clear context
Context admin clear
Treeclear
Introduced25.3.R2

Platforms

7705 SAR Gen 2

security
Synopsis Enter the security context
Context admin clear security
Treesecurity
Introduced25.3.R2

Platforms

7705 SAR Gen 2

lockout
Synopsis Reset the lockout timer
Context admin clear security lockout
Treelockout
Introduced25.3.R2

Platforms

7705 SAR Gen 2

all
Synopsis Clear lockout of all users
Context admin clear security lockout all
Treeall

Notes

The following elements are part of a mandatory choice: all or user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

user named-item
Synopsis User to be cleared of lockout
Context admin clear security lockout user named-item
Treeuser
String length1 to 32

Notes

The following elements are part of a mandatory choice: all or user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

password-history
Synopsis Clear the password history
Context admin clear security password-history
Treepassword-history
Introduced25.3.R2

Platforms

7705 SAR Gen 2

all
Synopsis Clear password history of all users
Context admin clear security password-history all
Treeall

Notes

The following elements are part of a mandatory choice: all or user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

user named-item
Synopsis User to be cleared of password history information
Contextadmin clear security password-history user named-item
Treeuser
String length1 to 32

Notes

The following elements are part of a mandatory choice: all or user.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

disconnect

Synopsis Disconnect a user session
Context admin disconnect
Treedisconnect
Introduced25.3.R2

Platforms

7705 SAR Gen 2

address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address of the session to disconnect
Contextadmin disconnect address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeaddress
Introduced25.3.R2

Platforms

7705 SAR Gen 2

op-table-bypass boolean
Synopsis Avoid operation ID allocation
Context admin disconnect op-table-bypass boolean
Treeop-table-bypass

Description

When configured to true, the system bypasses the YANG-based operations infrastructure and avoids the allocation of an operation ID. This is useful if the global operations table is full and a delete operation or admin disconnect is required.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

session-id number
Synopsis ID of the session to disconnect
Context admin disconnect session-id number
Treesession-id
Range1 to 4294967295
Introduced25.3.R2

Platforms

7705 SAR Gen 2

session-type keyword
Synopsis Type of session to disconnect
Context admin disconnect session-type keyword
Treesession-type
Optionsconsole, bluetooth, telnet, ssh, ftp, netconf, grpc, cron-ehs
Introduced 25.3.R2

Platforms

7705 SAR Gen 2

username named-item
Synopsis Username to disconnect
Context admin disconnect username named-item
Treeusername
String length1 to 32
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipsec

Synopsis Perform IPsec operations
Context admin ipsec
Treeipsec
Introduced25.3.R2

Platforms

7705 SAR Gen 2

show
Synopsis Display IPsec information
Context admin ipsec show
Treeshow
Introduced25.3.R2

Platforms

7705 SAR Gen 2

key
Synopsis Display IPsec key history
Context admin ipsec show key
Treekey
Introduced25.3.R2

Platforms

7705 SAR Gen 2

gateway named-item
Synopsis IPsec gateway name
Context admin ipsec show key gateway named-item
Treegateway
String length1 to 32

Notes

The following elements are part of a mandatory choice: (gateway, peer-tunnel-ip-address, and peer-tunnel-port), ip-tunnel, or ipsec-tunnel.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-tunnel interface-name
Synopsis IPsec transport mode IP tunnel name
Context admin ipsec show key ip-tunnel interface-name
Treeip-tunnel
String length1 to 32

Notes

The following elements are part of a mandatory choice: (gateway, peer-tunnel-ip-address, and peer-tunnel-port), ip-tunnel, or ipsec-tunnel.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ipsec-tunnel named-item
Synopsis IPsec tunnel name
Context admin ipsec show key ipsec-tunnel named-item
Treeipsec-tunnel
String length1 to 32

Notes

The following elements are part of a mandatory choice: (gateway, peer-tunnel-ip-address, and peer-tunnel-port), ip-tunnel, or ipsec-tunnel.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

peer-tunnel-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis Dynamic tunnel IP address
Context admin ipsec show key peer-tunnel-ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treepeer-tunnel-ip-address

Notes

The following elements are part of a mandatory choice: (gateway, peer-tunnel-ip-address, and peer-tunnel-port), ip-tunnel, or ipsec-tunnel.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

peer-tunnel-port number
Synopsis Dynamic tunnel port
Context admin ipsec show key peer-tunnel-port number
Treepeer-tunnel-port
Range0 | 1 to 65535

Notes

The following elements are part of a mandatory choice: (gateway, peer-tunnel-ip-address, and peer-tunnel-port), ip-tunnel, or ipsec-tunnel.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

type keyword
Synopsis Key type
Contextadmin ipsec show key type keyword
Treetype
Optionsike, child

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

reboot

Synopsis Reboot CPM or force an upgrade of system boot ROMs
Contextadmin reboot
Treereboot
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[card] keyword
Synopsis Card to reboot
Contextadmin reboot [card] keyword
Tree[card]
Optionsactive, standby, upgrade
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hold
Synopsis Hold a rebooted standby CPM from coming back online
Contextadmin reboot hold
Treehold
Introduced25.3.R2

Platforms

7705 SAR Gen 2

now
Synopsis Reboot immediately without prompts or confirmation
Contextadmin reboot now
Treenow
Introduced25.3.R2

Platforms

7705 SAR Gen 2

redundancy

Synopsis Enter the redundancy context
Context admin redundancy
Treeredundancy
Introduced25.3.R2

Platforms

7705 SAR Gen 2

synchronize
Synopsis Synchronize the standby CPM
Context admin redundancy synchronize
Treesynchronize
Introduced25.3.R2

Platforms

7705 SAR Gen 2

boot-environment
Synopsis Synchronize all files required for the boot process
Contextadmin redundancy synchronize boot-environment
Treeboot-environment

Notes

The following elements are part of a mandatory choice: boot-environment, certificate, or configuration.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

certificate
Synopsis Synchronize imported certificate, key, and CRL files
Contextadmin redundancy synchronize certificate
Treecertificate

Notes

The following elements are part of a mandatory choice: boot-environment, certificate, or configuration.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

configuration
Synopsis Synchronize the configuration files
Context admin redundancy synchronize configuration
Treeconfiguration

Description

When specified, the system synchronizes the primary, secondary, and tertiary configuration files.

Notes

The following elements are part of a mandatory choice: boot-environment, certificate, or configuration.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

save

Synopsis Perform configuration save operations
Contextadmin save
Treesave
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bof
Synopsis Save the BOF region configuration
Context admin save bof
Treebof

Notes

The following elements are part of a choice: bof, configure, debug, or li.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

cleartext
Synopsis Force the configuration to be saved in clear text
Contextadmin save cleartext
Treecleartext
Introduced25.3.R2

Platforms

7705 SAR Gen 2

configure
Synopsis Save the configure region configuration
Contextadmin save configure
Treeconfigure

Notes

The following elements are part of a choice: bof, configure, debug, or li.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

debug
Synopsis Save the debug region configuration
Context admin save debug
Treedebug

Notes

The following elements are part of a choice: bof, configure, debug, or li.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[url] string
Synopsis Location to save the configuration
Context admin save [url] string
Tree[url]
Introduced25.3.R2

Platforms

7705 SAR Gen 2

set

Synopsis Enter the set context
Context admin set
Treeset
Introduced25.3.R2

Platforms

7705 SAR Gen 2

time
Synopsis System date and time
Context admin set time
Treetime
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[system-time] date-and-time
Synopsis System date and time
Context admin set time [system-time] date-and-time
Tree[system-time]

Description

This command sets the system date and time. The time zone may optionally be specified. When the time zone is not specified, the system uses the configured system time zone.

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

show

Synopsis Enter the show context
Context admin show
Treeshow

Description

The admin show commands display the same configuration as the info command but are not subject to command authorization and do not require configuration mode access.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

configuration
Synopsis Show the current configuration
Context admin show configuration
Treeconfiguration
Introduced25.3.R2

Platforms

7705 SAR Gen 2

bof
Synopsis Show the BOF region configuration
Context admin show configuration bof
Treebof

Notes

The following elements are part of a choice: bof, configure, debug, or li.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

booted
Synopsis Show the booted BOF configuration
Context admin show configuration booted
Treebooted

Notes

The following elements are part of a choice: booted or cflash-id.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

cflash-id cflash-id
Synopsis Show the BOF configuration file on a compact flash
Contextadmin show configuration cflash-id cflash-id
Treecflash-id
String length4 to 6

Notes

The following elements are part of a choice: booted or cflash-id.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

configure
Synopsis Show the configure region configuration
Contextadmin show configuration configure
Treeconfigure

Notes

The following elements are part of a choice: bof, configure, debug, or li.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

debug
Synopsis Show the debug region configuration
Context admin show configuration debug
Treedebug

Notes

The following elements are part of a choice: bof, configure, debug, or li.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

depth number
Synopsis Depth limit from the pwc
Context admin show configuration depth number
Treedepth
Range1 to 4294967040
Introduced25.3.R2

Platforms

7705 SAR Gen 2

flat
Synopsis Show the context from the pwc on each line
Contextadmin show configuration flat
Treeflat

Notes

The following elements are part of a choice: flat, full-context, json, or xml.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

full-context
Synopsis Show the full context on each line
Context admin show configuration full-context
Treefull-context

Notes

The following elements are part of a choice: flat, full-context, json, or xml.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

inheritance
Synopsis Include configuration inherited from configuration groups
Contextadmin show configuration inheritance
Treeinheritance

Description

This option specifies the inclusion of configuration inherited from configuration groups in the output.

This option should only be used in the configure region when configuration groups are used. The output with this option is the same as admin show configuration when used in other configuration regions.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

intended
Synopsis Show the intended configuration
Context admin show configuration intended
Treeintended

Notes

The following elements are part of a choice: intended or running.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

json
Synopsis Show the output in indented JSON format
Contextadmin show configuration json
Treejson

Notes

The following elements are part of a choice: flat, full-context, json, or xml.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

running
Synopsis Show the running configuration
Context admin show configuration running
Treerunning

Notes

The following elements are part of a choice: intended or running.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

xml
Synopsis Show the output in indented XML format
Contextadmin show configuration xml
Treexml

Notes

The following elements are part of a choice: flat, full-context, json, or xml.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

support-mode

Synopsis Enable technical support commands
Context admin support-mode
Treesupport-mode

Description

Commands in this context enable the kernel and shell commands used only by Nokia technical support for troubleshooting.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

disable
Synopsis Disable technical support commands
Context admin support-mode disable
Treedisable

Description

This command disables the kernel and shell commands used only by Nokia technical support for troubleshooting.

Notes

The following elements are part of a choice: disable, kernel, or shell.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

kernel
Synopsis Kernel command password
Context admin support-mode kernel
Treekernel

Description

This command allows Nokia technical support to access the kernel commands. kernel commands are used only by Nokia technical support for troubleshooting.

Notes

The following elements are part of a choice: disable, kernel, or shell.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

password encrypted-leaf
Synopsis Kernel command password
Context admin support-mode kernel password encrypted-leaf
Treepassword

Description

This command specifies the password to access kernel commands.

This command is used only by Nokia technical support for troubleshooting.

String length1 to 199
Introduced25.3.R2

Platforms

7705 SAR Gen 2

shell
Synopsis Shell command password
Context admin support-mode shell
Treeshell

Description

This command allows Nokia technical support to access the shell commands. shell commands are used only by Nokia technical support for troubleshooting.

Notes

The following elements are part of a choice: disable, kernel, or shell.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

password encrypted-leaf
Synopsis Shell command password
Context admin support-mode shell password encrypted-leaf
Treepassword

Description

This command specifies the password to access the shell commands.

This command is used only by Nokia technical support for troubleshooting.

String length1 to 199
Introduced25.3.R2

Platforms

7705 SAR Gen 2

system

Synopsis Enter the system context
Context admin system
Treesystem
Introduced25.3.R2

Platforms

7705 SAR Gen 2

license
Synopsis Enter the license context
Context admin system license
Treelicense
Introduced25.3.R2

Platforms

7705 SAR Gen 2

clear
Synopsis Clear system license
Context admin system license clear
Treeclear

Description

This command removes the entitlements that were installed using a license file.

All the entitlements must be unallocated; otherwise, the command fails.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

management-interface
Synopsis Enter the management-interface context
Contextadmin system management-interface
Treemanagement-interface
Introduced25.3.R2

Platforms

7705 SAR Gen 2

commit
Synopsis Enter the commit context
Context admin system management-interface commit
Treecommit
Introduced25.3.R2

Platforms

7705 SAR Gen 2

confirmed
Synopsis Enter the confirmed context
Context admin system management-interface commit confirmed
Treeconfirmed

Description

Commands in this context accept or cancel a confirmed commit that is in progress and that was started by another configuration session.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

operations
Synopsis Enter the operations context
Context admin system management-interface operations
Treeoperations

Description

Commands in this context are used to manage YANG-based operations (for example, admin reboot, or ping) in model-driven interfaces.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

delete-operation
Synopsis Stop and remove an operation
Context admin system management-interface operations delete-operation
Treedelete-operation

Description

This command removes an operation and all status and data associated with it. If the operation was executing, it is stopped before removal.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

op-table-bypass boolean
Synopsis Avoid operation ID allocation
Context admin system management-interface operations delete-operation op-table-bypass boolean
Treeop-table-bypass

Description

When configured to true, the system bypasses the YANG-based operations infrastructure and avoids the allocation of an operation ID. This is useful if the global operations table is full and a delete operation or admin disconnect is required.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

stop-operation
Synopsis Stop the execution of an operational command
Contextadmin system management-interface operations stop-operation
Treestop-operation

Description

This command stops the execution of an operational command.

An operation launched as "asynchronous" is not deleted from the system when it is stopped. Status and other data associated with the operation persist until the operation is explicitly deleted using the delete operation command or a retention timeout.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

op-table-bypass boolean
Synopsis Avoid operation ID allocation
Context admin system management-interface operations stop-operation op-table-bypass boolean
Treeop-table-bypass

Description

When configured to true, the system bypasses the YANG-based operations infrastructure and avoids the allocation of an operation ID. This is useful if the global operations table is full and a delete operation or admin disconnect is required.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

security
Synopsis Enter the security context
Context admin system security
Treesecurity
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hash-control
Synopsis Enter the hash-control context
Contextadmin system security hash-control
Treehash-control
Introduced25.3.R2

Platforms

7705 SAR Gen 2

custom-hash
Synopsis Custom encryption
Context admin system security hash-control custom-hash
Treecustom-hash
Introduced25.3.R2

Platforms

7705 SAR Gen 2

algorithm keyword
Synopsis Algorithm for custom encryption
Context admin system security hash-control custom-hash algorithm keyword
Treealgorithm

Description

This command configures the algorithm for custom encryption. The encryption uses ECB mode, PKCS#7 padding, and Base64 encoding.

Options

3des – DES-EDE3-ECB with PKCS #5 padding

aes128 – AES-128-ECB with PKCS #7 padding

aes192 – AES-192-ECB with PKCS #7 padding

aes256 – AES-256-ECB with PKCS #7 padding

Notes

This element is mandatory.

Platforms

7705 SAR Gen 2

os-security
Synopsis Perform operating-system-level security operations
Contextadmin system security os-security
Treeos-security
Introduced25.3.R2

Platforms

7705 SAR Gen 2

anti-theft
Synopsis Perform anti-theft operations
Context admin system security os-security anti-theft
Treeanti-theft
Introduced25.3.R2

Platforms

7705 SAR Gen 2

activate
Synopsis Enable anti-theft for the specified CPM card
Contextadmin system security os-security anti-theft activate
Treeactivate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

force
Synopsis Proceed without further prompting from the system
Contextadmin system security os-security anti-theft activate force
Treeforce

Description

When configured, this command ignores further prompts from the system. This command is required for non-interactive interfaces.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

deactivate
Synopsis Disables anti-theft for the specified CPM card
Contextadmin system security os-security anti-theft deactivate
Treedeactivate
Introduced25.3.R2

Platforms

7705 SAR Gen 2

force
Synopsis Proceed without further prompting from the system
Contextadmin system security os-security anti-theft deactivate force
Treeforce

Description

When configured, this command ignores further prompts from the system. This command is required for non-interactive interfaces.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

remove-password
Synopsis Remove the OS security password
Context admin system security os-security remove-password
Treeremove-password

Description

When configured, this command removes the OS security password. Any applications using the password must first be disabled before removing the password. Anti-theft must be deactivated to remove the OS security password.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

force
Synopsis Proceed without further prompting from the system
Contextadmin system security os-security remove-password force
Treeforce

Description

When configured, this command ignores further prompts from the system. This command is required for non-interactive interfaces.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

set-password
Synopsis Configure the password used to protect the system
Contextadmin system security os-security set-password
Treeset-password

Description

When configured, if there was no password previously configured, a new password must be configured using using the new-password command. If a password has already been configured, the user must enter the current-password.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

force
Synopsis Proceed without further prompting from the system
Contextadmin system security os-security set-password force
Treeforce

Description

When configured, this command ignores the requirement to enter the new-password twice. Configuring this command is required for non-interactive interfaces.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

new-password anti-theft-password-cleartext
Synopsis New OS security password
Context admin system security os-security set-password new-password anti-theft-password-cleartext
Treenew-password

Description

This command configures the new OS security password. When configured, the user is prompted to reenter the new password.

String length8 to 32
Introduced25.3.R2

Platforms

7705 SAR Gen 2

pki
Synopsis Perform PKI related operations
Context admin system security pki
Treepki

Description

Commands in this context specify options for public key infrastructure operations.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

cmpv2
Synopsis Perform CMPv2 operations
Context admin system security pki cmpv2
Treecmpv2

Description

Commands in this context specify options for Certificate Management Protocol v2 (CMPv2) operations.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

cert-request
Synopsis Request an additional certificate
Context admin system security pki cmpv2 cert-request
Treecert-request

Description

When specified, the system requests an additional certificate after the initial certificate has been obtained from the CA.

The request is authenticated by a signature signed by the current key, along with the current certificate. The hash algorithm used for the signature depends on the key type:

  • DSA key - SHA1

  • RSA key: MD5 | SHA1 | SHA224 | SHA256 | SHA384 | SHA512 (default is SHA1)

  • ECDSA key: SHA1 | SHA224 | SHA256 | SHA384 | SHA512 (default is SHA256)

CA may not return a certificate immediately, for example, if the request process requires manual intervention. The poll command can be used to poll the status of the request.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ca-profile reference
Synopsis PKI CA profile name
Context admin system security pki cmpv2 cert-request ca-profile reference
Treeca-profile

Description

This command configures the CA profile that contains the CMPv2 configuration like server URL.

Reference

state system security pki ca-profile named-item

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

current-key pki-file-name
Synopsis Imported key file used to create the request
Contextadmin system security pki cmpv2 cert-request current-key pki-file-name
Treecurrent-key

Description

This command specifies the imported key file corresponding to the existing imported certificate file used to create the request.

String length1 to 95

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

domain-name string
Synopsis FQDNs for the Subject Alternative Name
Contextadmin system security pki cmpv2 cert-request domain-name string
Treedomain-name

Description

This command specifies the Fully Qualified Domain Names (FQDNs) for the Subject Alternative Name extension of the requesting certificate, separated by commas.

String length1 to 512
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address for the Subject Alternative Name
Contextadmin system security pki cmpv2 cert-request ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeip-address

Description

This command specifies an IPv4 or IPv6 address for the Subject Alternative Name extension of the requesting certificate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

subject-dn string
Synopsis Subject of the requesting certificate
Contextadmin system security pki cmpv2 cert-request subject-dn string
Treesubject-dn

Description

This command specifies the subject DN attributes used in the certificate request. The format is a comma separated list with the format attr1=val1, attr2=val2, where attrN={C | ST | O | OU | CN}.

String length1 to 256
Introduced25.3.R2

Platforms

7705 SAR Gen 2

clear-request
Synopsis Clear pending CMPv2 requests
Context admin system security pki cmpv2 clear-request
Treeclear-request

Description

When specified, the system clears pending CMPv2 requests for the specified CA. If no requests are pending, the system clears the saved result of the previous request

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ca-profile reference
Synopsis PKI CA profile name
Context admin system security pki cmpv2 clear-request ca-profile reference
Treeca-profile

Description

This command configures the CA profile that contains the CMPv2 configuration like server URL.

Reference

state system security pki ca-profile named-item

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

initial-registration
Synopsis Request initial certificate using the CMPv2 protocol
Contextadmin system security pki cmpv2 initial-registration
Treeinitial-registration

Description

When specified, the system requests the initial certificate from the CA using the CMPv2 initial registration procedure.

The ca-profile parameter specifies a CA profile which includes CMP server information.

The key-to-certify parameter is an imported key file to be certified by the CA.

The request is authenticated via one of the following methods:

  • A password and a reference number that pre-distributed by CA via out-of-band means. The specified password and reference number are not necessarily in the key-list configured in the corresponding CA-Profile. If key-list is not configured in the corresponding CA profile, the system uses the existing password to authenticate the CMPv2 packets from server if it is in password protection. If key-list is configured in the corresponding CA profile and the server does not send SenderKID, the system uses the lexicographical first key in the key-list to authenticate the CMPv2 packets from the server in case it is in password protection mode.

  • A signature signed by the protection-key or key-to-certify, optionally with with the corresponding certificate. If the protection-key command is not specified, the system uses the key-to-certify configuration for message protection. The hash algorithm used for the signature depends on the key type. See the cert-request command for details. Optionally, the system may send a certificate or a chain of certificates in the extraCertsfield. The certificate is specified by the certificate parameter and must include the public key of the key used for message protection. Sending a chain is enabled by specifying the send-chain and with-ca command options.

The subject-dn command specifies the subject of the requesting certificate.

The save-as command specifies the full path name for saving the result certificate.

The CA may not return the certificate immediately, for example, if the request process requires manual intervention. In such cases, the poll command can be used to poll the status of the request.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ca-profile reference
Synopsis PKI CA profile name
Context admin system security pki cmpv2 initial-registration ca-profile reference
Treeca-profile

Description

This command configures the CA profile that contains the CMPv2 configuration like server URL.

Reference

state system security pki ca-profile named-item

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

certificate pki-file-name
Synopsis Filename of the certificate for the protection key
Contextadmin system security pki cmpv2 initial-registration certificate pki-file-name
Treecertificate
String length1 to 95

Notes

The following elements are part of a mandatory choice: (certificate, hash-algorithm, protection-key, send-chain, and with-ca) or (password and reference).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

domain-name string
Synopsis FQDNs for the Subject Alternative Name
Contextadmin system security pki cmpv2 initial-registration domain-name string
Treedomain-name

Description

This command specifies the Fully Qualified Domain Names (FQDNs) for the Subject Alternative Name extension of the requesting certificate, separated by commas.

String length1 to 512
Introduced25.3.R2

Platforms

7705 SAR Gen 2

hash-algorithm keyword
Synopsis Hash algorithm used for the certificate signature
Contextadmin system security pki cmpv2 initial-registration hash-algorithm keyword
Treehash-algorithm
Optionsmd5, sha1, sha224, sha256, sha384, sha512

Notes

The following elements are part of a mandatory choice: (certificate, hash-algorithm, protection-key, send-chain, and with-ca) or (password and reference).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address for the Subject Alternative Name
Contextadmin system security pki cmpv2 initial-registration ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeip-address

Description

This command specifies an IPv4 or IPv6 address for the Subject Alternative Name extension of the requesting certificate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

password string
Synopsis Password for message protection
Context admin system security pki cmpv2 initial-registration password string
Treepassword
String length1 to 64

Notes

The following elements are part of a mandatory choice: (certificate, hash-algorithm, protection-key, send-chain, and with-ca) or (password and reference).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

protection-key pki-file-name
Synopsis Key file used to generate message protection signature
Contextadmin system security pki cmpv2 initial-registration protection-key pki-file-name
Treeprotection-key
String length1 to 95

Notes

The following elements are part of a mandatory choice: (certificate, hash-algorithm, protection-key, send-chain, and with-ca) or (password and reference).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

reference string
Synopsis Password reference number
Context admin system security pki cmpv2 initial-registration reference string
Treereference
String length1 to 64

Notes

The following elements are part of a mandatory choice: (certificate, hash-algorithm, protection-key, send-chain, and with-ca) or (password and reference).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

subject-dn string
Synopsis Subject of the requesting certificate
Contextadmin system security pki cmpv2 initial-registration subject-dn string
Treesubject-dn

Description

This command specifies the subject DN attributes used in the certificate request. The format is a comma separated list with the format attr1=val1, attr2=val2, where attrN={C | ST | O | OU | CN}.

String length1 to 256
Introduced25.3.R2

Platforms

7705 SAR Gen 2

with-ca reference
Synopsis Name of CA profile with certificate in the send chain
Contextadmin system security pki cmpv2 initial-registration with-ca reference
Treewith-ca

Reference

state system security pki ca-profile named-item

Notes

The following elements are part of a mandatory choice: (certificate, hash-algorithm, protection-key, send-chain, and with-ca) or (password and reference).

Introduced25.3.R2

Platforms

7705 SAR Gen 2

key-update
Synopsis Request new certificate to update existing certificate
Contextadmin system security pki cmpv2 key-update
Treekey-update

Description

When specified, the system requests a new certificate from the CA to update an existing certificate due to reasons such as a key refresh or to replace a compromised key.

The CA may not return the certificate immediately, for example, if the request process requires manual intervention. In these cases, the poll command can be used to poll the status of the request.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ca-profile reference
Synopsis PKI CA profile name
Context admin system security pki cmpv2 key-update ca-profile reference
Treeca-profile

Description

This command configures the CA profile that contains the CMPv2 configuration like server URL.

Reference

state system security pki ca-profile named-item

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

new-key pki-file-name
Synopsis Name of new imported key file used for the key update
Contextadmin system security pki cmpv2 key-update new-key pki-file-name
Treenew-key
String length1 to 95

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

poll
Synopsis Poll the CMPv2 server for pending request status
Contextadmin system security pki cmpv2 poll
Treepoll

Description

When specified, the system polls the status of the pending CMPv2 request toward the specified CA.

If the response is ready, the system resumes the CMPv2 protocol exchange with the server.

SR OS allows only one pending CMP request per CA; therefore, no new request is allowed when a pending request is present.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ca-profile reference
Synopsis PKI CA profile name
Context admin system security pki cmpv2 poll ca-profile reference
Treeca-profile

Description

This command configures the CA profile that contains the CMPv2 configuration like server URL.

Reference

state system security pki ca-profile named-item

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

convert-file
Synopsis Convert imported file between secure and legacy format
Contextadmin system security pki convert-file
Treeconvert-file
Introduced25.3.R2

Platforms

7705 SAR Gen 2

force
Synopsis Force the conversion
Context admin system security pki convert-file force
Treeforce

Description

When specified, the system forces the conversion of imported certificates and keys even if files with the same output names exist.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

[output-file] pki-file-name
Synopsis Output filename
Context admin system security pki convert-file [output-file] pki-file-name
Tree[output-file]

Description

This command specifies the output filename. If the filename already exists, the system prompts the user to proceed or aborts if the force command is unconfigured.

String length1 to 95

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

crl-update
Synopsis Trigger the CRL update for the CA profile
Contextadmin system security pki crl-update
Treecrl-update
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ca-profile reference
Synopsis PKI CA profile name
Context admin system security pki crl-update ca-profile reference
Treeca-profile

Description

This command configures the CA profile that contains the CMPv2 configuration like server URL.

Reference

state system security pki ca-profile named-item

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

est
Synopsis Perform Enrollment over Secure Transport operations
Contextadmin system security pki est
Treeest

Description

Commands in this context configure command options for Enrollment over Secure Transport (EST) protocol operations.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ca-certificates
Synopsis Download CA certificates from the EST server
Contextadmin system security pki est ca-certificates
Treeca-certificates

Description

This command downloads a Certificate Authority (CA) certificate from an EST server specified by the profile name.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

enroll
Synopsis Enroll a new certificate with CA with the EST protocol
Contextadmin system security pki est enroll
Treeenroll

Description

When specified, the system enrolls a new certificate with Certificate Authority (CA) by the EST protocol specified with the est-profile command with a imported private key specified by the key command.

The est-profile commad specifies the authentication between the system and EST server.

The hash-alg, subject-dn, domain-name, and ip-address commands are used to generate the Certificate Signing Request (CSR) in the EST request message. The domain-name and ip-address commands are used as subject alternative names.

If validate-certificate-chain is specified, the system validates the chain of result certificate before importing it. The certificate chain is the chain of all certificates from the result certificate to the issuing CA. The result certificate is the new certificate returned by the EST server.

The result certificate is imported and saved with the filename specified by the output-file command. If the force command is specified, the system overwrites the existing file with same name as the output file.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

domain-name string
Synopsis FQDNs for the Subject Alternative Name
Contextadmin system security pki est enroll domain-name string
Treedomain-name

Description

This command specifies the Fully Qualified Domain Names (FQDNs) for the Subject Alternative Name extension of the requesting certificate, separated by commas.

String length1 to 512
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address for the Subject Alternative Name
Contextadmin system security pki est enroll ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeip-address

Description

This command specifies an IPv4 or IPv6 address for the Subject Alternative Name extension of the requesting certificate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

key cflash-url
Synopsis Name of the imported the key file to enroll
Contextadmin system security pki est enroll key cflash-url
Treekey
String length1 to 200

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

subject-dn string
Synopsis Subject of the requesting certificate
Contextadmin system security pki est enroll subject-dn string
Treesubject-dn

Description

This command specifies the subject DN attributes used in the certificate request. The format is a comma separated list with the format attr1=val1, attr2=val2, where attrN={C | ST | O | OU | CN}.

String length1 to 256
Introduced25.3.R2

Platforms

7705 SAR Gen 2

renew
Synopsis Renew a CA certificate using the EST protocol
Contextadmin system security pki est renew
Treerenew

Description

When specified, the system renews an imported certificate (specified by the certificate command) with a Certificate Authority (CA) using the EST protocol specified by the est-profile parameter, with an imported private key specified the key command. The key can be either the key of the certificate to be renewed or a new key.

The authentication between system and EST server is specified by the est-profile parameter.

The system uses the hash-alg command to generate the CSR in the EST request message.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

key cflash-url
Synopsis Imported key file of the certificate to renew
Contextadmin system security pki est renew key cflash-url
Treekey
String length1 to 200

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

export
Synopsis Export an imported file
Context admin system security pki export
Treeexport
Introduced25.3.R2

Platforms

7705 SAR Gen 2

format keyword
Synopsis Output file format
Context admin system security pki export format keyword
Treeformat
Optionspkcs12, pkcs7-der, pkcs7-pem, pem, der

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

input-file pki-file-name
Synopsis Name of the file to be exported
Context admin system security pki export input-file pki-file-name
Treeinput-file
String length1 to 95

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

key-file pki-file-name
Synopsis Name of the key file to be exported
Context admin system security pki export key-file pki-file-name
Treekey-file

Description

This command specifies the name of the key file to be exported when the output format may contain the certificate and the key.

String length1 to 95
Introduced25.3.R2

Platforms

7705 SAR Gen 2

output-url cflash-url
Synopsis Full path to export the result file
Context admin system security pki export output-url cflash-url
Treeoutput-url
String length1 to 200

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

type keyword
Synopsis Type of file to be exported
Context admin system security pki export type keyword
Treetype
Optionscertificate, key, crl

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

generate-csr
Synopsis Generate a PKCS#10 certificate signing request file
Contextadmin system security pki generate-csr
Treegenerate-csr
Introduced25.3.R2

Platforms

7705 SAR Gen 2

domain-name string
Synopsis FQDNs for the Subject Alternative Name
Contextadmin system security pki generate-csr domain-name string
Treedomain-name

Description

This command specifies the Fully Qualified Domain Names (FQDNs) for the Subject Alternative Name extension of the requesting certificate, separated by commas.

String length1 to 512
Introduced25.3.R2

Platforms

7705 SAR Gen 2

ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Synopsis IP address for the Subject Alternative Name
Contextadmin system security pki generate-csr ip-address (ipv4-address-no-zone | ipv6-address-no-zone)
Treeip-address

Description

This command specifies an IPv4 or IPv6 address for the Subject Alternative Name extension of the requesting certificate.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

key-url cflash-url
Synopsis Full path to the key file used to generate the request
Contextadmin system security pki generate-csr key-url cflash-url
Treekey-url
String length1 to 200

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

subject-dn string
Synopsis Subject of the requesting certificate
Contextadmin system security pki generate-csr subject-dn string
Treesubject-dn

Description

This command specifies the subject DN attributes used in the certificate request. The format is a comma separated list with the format attr1=val1, attr2=val2, where attrN={C | ST | O | OU | CN}.

String length1 to 256
Introduced25.3.R2

Platforms

7705 SAR Gen 2

use-printable
Synopsis Force ASCII encoding for input subject DN attributes
Contextadmin system security pki generate-csr use-printable
Treeuse-printable

Description

When specified, the system forces the use of ASCII encoding for the input subject DN attributes. Otherwise, the system uses UTF-8 encoding.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

generate-keypair
Synopsis Generate PKI key pair
Context admin system security pki generate-keypair
Treegenerate-keypair

Description

When specified, the system generates an RSA, DSA, or ECDSA private/public key pair file

Introduced25.3.R2

Platforms

7705 SAR Gen 2

dsa-key-size number
Synopsis Length of the DSA key to be generated
Contextadmin system security pki generate-keypair dsa-key-size number
Treedsa-key-size
Range512 to 8192
Default2048

Notes

The following elements are part of a mandatory choice: dsa-key-size, ecdsa-curve, or rsa-key-size.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

ecdsa-curve keyword
Synopsis Elliptic curve of the ECDSA key to be generated
Contextadmin system security pki generate-keypair ecdsa-curve keyword
Treeecdsa-curve
Optionssecp256r1, secp384r1, secp521r1
Defaultsecp256r1

Notes

The following elements are part of a mandatory choice: dsa-key-size, ecdsa-curve, or rsa-key-size.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

rsa-key-size number
Synopsis Length of the RSA key to be generated
Contextadmin system security pki generate-keypair rsa-key-size number
Treersa-key-size
Range512 to 8192
Default2048

Notes

The following elements are part of a mandatory choice: dsa-key-size, ecdsa-curve, or rsa-key-size.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

import
Synopsis Import a certificate related file
Context admin system security pki import
Treeimport

Description

When specified, the system imports an input file (key/certificate/CRL) to be used by SROS applications. The following summarizes the supported formats:

  • Certificate - PKCS #12, PKCS #7 PEM encoded, PKCS #7 DER encoded, PEM, DER

  • Key - PKCS #12, PEM, DER

  • CRL - PKCS #7 PEM encoded, PKCS #7 DER encoded, PEM, DER

Introduced25.3.R2

Platforms

7705 SAR Gen 2

format keyword
Synopsis Output file format
Context admin system security pki import format keyword
Treeformat
Optionspkcs12, pkcs7-der, pkcs7-pem, pem, der

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

input-url cflash-url
Synopsis Full path to the file to import
Context admin system security pki import input-url cflash-url
Treeinput-url
String length1 to 200

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

type keyword
Synopsis Type of file to be exported
Context admin system security pki import type keyword
Treetype
Optionscertificate, key, crl

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

reload
Synopsis Reload key or certificate files
Context admin system security pki reload
Treereload

Description

When specified, the system reloads the key or certificate files for the specified application.This command can be used to ensure a changed imported file takes effect.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

certificate pki-file-name
Synopsis Name of the certificate file to reload
Contextadmin system security pki reload certificate pki-file-name
Treecertificate
String length1 to 95

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

key pki-file-name
Synopsis Name of the key file to reload
Context admin system security pki reload key pki-file-name
Treekey
String length1 to 95

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

show
Synopsis Enter the show context
Context admin system security pki show
Treeshow

Description

Commands in this context include operations to display the PKI file.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

file-content
Synopsis Display content of certificate related files
Contextadmin system security pki show file-content
Treefile-content
Introduced25.3.R2

Platforms

7705 SAR Gen 2

format keyword
Synopsis Format of the file to display
Context admin system security pki show file-content format keyword
Treeformat
Optionspkcs10, pkcs12, pkcs7-der, pkcs7-pem, pem, der

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

type keyword
Synopsis Type of the file to display
Context admin system security pki show file-content type keyword
Treetype
Optionscertificate, key, crl, csr

Notes

This element is mandatory.

Introduced 25.3.R2

Platforms

7705 SAR Gen 2

update-certificate
Synopsis Update End Entity certificate
Context admin system security pki update-certificate
Treeupdate-certificate

Description

When specified, the system triggers an update for the specified certificate according to the corresponding configure system security pki certificate-auto-update configuration.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

certificate reference
Synopsis Name of the certificate file to be updated
Contextadmin system security pki update-certificate certificate reference
Treecertificate

Reference

state system security pki certificate-auto-update pki-file-name

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

secure-boot
Synopsis Enter the secure-boot context
Context admin system security secure-boot
Treesecure-boot
Introduced25.3.R2

Platforms

7705 SAR Gen 2

activate
Synopsis Activate secure boot on a CPM
Context admin system security secure-boot activate
Treeactivate

Description

This command activates Secure Boot to enforce digital signature verification of the software on every boot.

Once Secure Boot is activated on a CPM, the capability is permanently enabled and cannot be disabled.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

card reference
Synopsis CPM slot where secure boot is activated or modified
Contextadmin system security secure-boot activate card reference
Treecard

Reference

state cpm cpm-card-slot

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

revoke-key
Synopsis Revoke secure boot keys
Context admin system security secure-boot revoke-key
Treerevoke-key
Introduced25.3.R2

Platforms

7705 SAR Gen 2

card reference
Synopsis CPM slot where secure boot is activated or modified
Contextadmin system security secure-boot revoke-key card reference
Treecard

Reference

state cpm cpm-card-slot

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

update-key
Synopsis Update secure boot keys
Context admin system security secure-boot update-key
Treeupdate-key
Introduced25.3.R2

Platforms

7705 SAR Gen 2

card reference
Synopsis CPM slot where secure boot is activated or modified
Contextadmin system security secure-boot update-key card reference
Treecard

Reference

state cpm cpm-card-slot

Notes

This element is mandatory.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

telemetry
Synopsis Enter the telemetry context
Context admin system telemetry
Treetelemetry
Introduced25.3.R2

Platforms

7705 SAR Gen 2

grpc
Synopsis Enter the grpc context
Context admin system telemetry grpc
Treegrpc
Introduced25.3.R2

Platforms

7705 SAR Gen 2

cancel
Synopsis Cancel the gRPC dynamic telemetry subscription
Contextadmin system telemetry grpc cancel
Treecancel
Introduced25.3.R2

Platforms

7705 SAR Gen 2

all
Synopsis Cancel gRPC dynamic telemetry for all subscriptions
Contextadmin system telemetry grpc cancel all
Treeall

Notes

The following elements are part of a mandatory choice: all or subscription-id.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

subscription-id number
Synopsis ID of the telemetry subscription to cancel
Contextadmin system telemetry grpc cancel subscription-id number
Treesubscription-id
Max. range0 to 4294967295

Notes

The following elements are part of a mandatory choice: all or subscription-id.

Introduced25.3.R2

Platforms

7705 SAR Gen 2

tech-support

Synopsis Save technical support information to a file
Contextadmin tech-support
Treetech-support
Introduced25.3.R2

Platforms

7705 SAR Gen 2

[url] url
Synopsis URL to save technical support information
Contextadmin tech-support [url] url
Tree[url]
String length1 to 180
Introduced25.3.R2

Platforms

7705 SAR Gen 2