Security Considerations

When enabled, RESTCONF services list on port 443 and utilize TLS for security. TLS requires a CA signed certificate for both the ICX and RESTCONF clients for mutual authentication.

For ease of use, the enforcement of TLS certificates can be relaxed by the way of configuration to allow clients to present self-signed certificates.

For ICX devices that do not have a RUCKUS-signed manufacturing certificate, the RESTCONF server will present a self-signed certificate needed by TLS. Otherwise, the manufacturing device certificate will be present by default.