Configuring an SSL Profile for Use with RADIUS Server Hosts

You must configure an SSL profile, to be applied to the RADIUS server, for use in establishing a secure TLS connection. The SSL profile specifies the root (CA) certificate trustpoint and the remote domain name to be used in certification.

  1. Name the SSL profile and enter profile configuration mode.
    device# configure terminal
    device(config)# ip ssl profile tls01
    
  2. Specify the trustpoint (CA server) that will be associated with the profile.
    device(config-ssl-tls01)# trustpoint TLS-ABCD
    
  3. Configure the remote domain name that the FQDN of the remote network peer certificate issues to the server. This is the 'reference identifier' that must appear in the network peer's certificate.
    Note: The ICX device expects the 'reference identifier' value to be either in CN, or, if SAN is present, this value must be shown as a DNS name in the SAN.
    Note: The remote domain name must match the CN or SAN. ICX devices do not support wild card bits in SAN extensions.
    device(config-ssl-tls01)# remotedomain ruckus.com
    device(config-ssl-tls01)# exit
    device(config)#
  4. (Optional) Use the show ip ssl profile command to check the user SSL profile and device SSL profile information.

The following example configures the SSL profile tls01 and associates it with the trustpoint TLS-ABCD with ruckus.com as the remote domain name that the end user certificate issues to the server.

device# configure terminal
device(config)# ip ssl profile tls01
device(config-ssl-tls01)# trustpoint TLS-ABCD
device(config-ssl-tls01)# remotedomain ruckus.com