Overview of ICX Digital Certificates

A RUCKUS ICX device requires a digital certificate to use certain applications. A digital certificate is required, for example, to use the ICX web interface or to monitor or configure an ICX device from SmartZone via ICX-Management. When a digital certificate is not present, these applications will not start or will not function as expected.

A valid certificate can be obtained in one of several ways.

  • TPM certificate - All new RUCKUS ICX devices are shipped from the factory with a TPM certificate. The Trusted Platform Module (TPM) provides a secure computing environment implemented in secure hardware.
  • IP SSL certificate - You can use available commands to import or remove an SSL certificate. Refer to SSL Security for more information.
  • External certificate - ICX devices can, when required, copy a certificate from an external source using available tftp commands.

Once a valid certificate is present, it remains available, unless the user erases startup configuration or uses a command to zeroize (clear) the certificate.

When no certificate is present, the RUCKUS ICX device is unable to use applications that require a certificate.

When more than one certificate is stored in the RUCKUS ICX device, the device selects the certificate for use based on the following order of priority:

  1. User-defined (SSL) certificate
  2. TPM certificate
  3. non-TPM (auto-generated legacy) certificate