ip ssl

Configures Secure Socket Layer (SSL) settings.
Syntax
ip ssl cert-key-size size
no ip ssl cert-key-size size
ip ssl { certificate-data-file | client-certificate | client-private-key | private-key-file } tftp { ipv4-address | ipv6 ipv6-address} file-name
no ip ssl { certificate-data-file | client-certificate | client-private-key | private-key-file } tftp { ipv4-address | ipv6 ipv6-address} file-name
ip ssl port port-num
no ip ssl port port-num
ip ssl certificate { common-name | country | locality | org | org-unit | state } name
no ip ssl certificate { common-name | country | locality | org | org-unit | state } name
Command Default

The default key size for RUCKUS-issued and imported digital certificates is 2048 bits.

By default, SSL protocol exchanges occur on TCP port 443.

The default TFTP server is not configured.

Parameters
cert-key-size size
Configures SSL server certificate key size. Valid values are 2048 and 4096.
certificate-data-file
Imports the server RSA certificate.
client-certificate
Imports the client RSA certificate.
client-private-key
Imports the client RSA private key.
private-key-file
Imports the server RSA private key.
tftp
Specifies that TFTP is used to import the certificates.
ipv4-address
Configures the IPv4 address of the TFTP server from which the certificates are imported.
ipv6 ipv6-address
Configures the IPv6 address of the TFTP server from which the certificates are imported.
file-name
The certificate data or key file name.
port port-num
Specifies the HTTPS/SSL port. The default port is 443.
certificate
Configures the SSL certificate generation signing request.
common-name

Specifies the common name, fully qualified domain name, or web address for which you plan to use your certificate.

country
Specifies the country name.
locality
Specifies the locality name.
org

Specifies the organization name.

org-unit
Specifies the organization unit name.
state
Specifies the state or province name.
name
Fully qualified domain name or web address for which you plan to use your certificate (for example, www.server.com) when used with common-name, two letter code country name (for example, US) when used with country, locality name (for example, city) when used with locality, organization name (for example, company) when used with org, organization unit name (for example, section) when used with org-unit, or province name (for example, California) when used with state.
Modes

Global configuration mode

Usage Guidelines

The SSL server certificate key size applies only to digital certificates issued by RUCKUS and does not apply to imported certificates.

To allow a client to communicate with another RUCKUS device using an SSL connection, you configure a set of digital certificates and RSA public-private key pairs on the device. A digital certificate is used for identifying the connecting client to the server. It contains information about the issuing Certificate Authority (CA) as well as a public key. You can import digital certificates and private keys from a server, or you can allow the device to create them. The RSA private key can be up to 4096 bits.

The no form of the command removes the configurations.

Examples

The following example shows how to import a digital certificate issued by a third-party Certificate Authority (CA) and save it in the flash memory.

device# configure terminal
device(config)# ip ssl certificate-data-file tftp 10.10.10.1 cacert.pem

The following example shows how to change the key size for RUCKUS-issued and imported digital certificates to 4096 bits.

device# configure terminal
device(config)# ip ssl cert-key-size 4096

The following example shows how to change the port number used for SSL communication.

device# configure terminal
device(config)# ip ssl port 334

The following example shows how to import an RSA private key from a client.

device# configure terminal
device(config)# ip ssl private-key-file tftp 192.168.9.210 keyfile

The following example shows how to configure the SSL certificate generation signing request for a country.

device# configure terminal
device(config)# ip ssl certificate country us