BSI Cloud Mode Limitations
The ECDSA certificate issued to the ICX device by SmartZone has the following limitations:
- The initial onboarding request from the ICX device to the SmartZone controller uses an existing RSA 2K encryption device certificate. The ECDSA private key sent from SmartZone to the ICX device is used to establish a reverse SSH tunnel. The ECDSA certificate is used to establish a TLS connection.
- The certificate is valid only for ICX communication within the same SmartZone cluster nodes.
- The certificate cannot be used for connecting to RUCKUS One or an Unleashed controller.
- The ICX device cannot use the certificate to connect to other applications, for example, to establish a Web UI or RESTCONF connection. ICX connections to these entities use the locally signed ECDSA certificate that was created to replace the manufacturer-installed RSA certificates.
- When the ICX functions as an NGINX server, it does not validate the client certificate. Any HTTPS copy operations also bypass server certificate validation.