WiNG How-To Guide Digital Certificates - Configuration
The following section outlines the configuration
steps required to add a Digital Certificate issued from a
Certification Authority onto a RF Switch:
1) Generating
Certificate Request [Section 3.1]:
2) Importing
Signed Certificates [Section 3.2]:
3) Assigning
Trustpoints [Section 3.3]
Generating a Certificate Request:
Before a certificate can be installed into a
trustpoint on the RF Switch, a certificate request must be generated. A
certificate request will generate a new certificate key and prepare a certificate
signing request (CSR) which can be entered into a Certificate Authority to
generate a server certificate.
The CSR contains information identifying the RF
Switch including information such as Company, Organization, Department, Country
and Locality. The CSR also include specific network level information about the
RF Switch such as IP Address, hostname and fully qualified domain name.When a
certificate signing request is generated, the RF Switch will generate a Base64
PKCS#10 binary encoded text which can be saved to the clipboard or file. The
PKCS#10 file can then be uploaded to a CA or the PKCS#10 file opened in a text
editor and the content copied and pasted into a form on the CA.
Web UI Configuration Example:
The following configuration example will demonstrate
how to create a trustpoint and generate a Certificate
Signing Request on the RF Switch using the Web UI:
Importing Signed Certificates:
Once a certificate has been issued form a CA, it
will need to be imported along with a CA root certificate into the trustpoint
on the RF Switch. Most CAs provide the ability to save an issued certificate in
numerous formats and care needs to be made to ensure that the issued server and
CA root certificates are saved using Base64 encoding. The Base64 encoded server
certificate and CA root certificate files can then be uploaded into the RF
Switch.
0 nhận xét:
Post a Comment