Configuring an SSL Profile for Use with Logging and RADIUS Server Hosts for NDcPP

Before configuring a server host, you must configure an SSL profile.

  1. Name the SSL profile and enter profile configuration mode.
    device# configure terminal
    device(config)# ip ssl profile tls01
    
    Syntax: ip ssl profile profile-name
    Syntax: no ip ssl profile profile-name
  2. Specify the trustpoint (CA server) that will be associated with the profile.
    device(config-ssl-tls01)# trustpoint TLS-ABCD
    
    Syntax: trustpoint trustpoint-name
    Syntax: no trustpoint trustpoint-name
  3. Configure the remote domain name that the FQDN of the remote network peer certificate issues to the server. This is the 'reference identifier' that must appear in the network peer's certificate.
    Note: The FastIron device expects the 'reference identifier' value to be either in CN, or, if SAN is present, this value must be shown as a DNS name in the SAN.
    device(config-ssl-tls01)# remotedomain ruckus.com
    
    Syntax: remotedomain domain-name
    Syntax: no remotedomain domain-name

The following example configures the SSL profile tls01 and associates it with the trustpoint TLS-ABCD with ruckus.com as the remote domain name that the end user certificate issues to the server.

device# configure terminal
device(config)# ip ssl profile tls01
device(config-ssl-tls01)# trustpoint TLS-ABCD
device(config-ssl-tls01)# remotedomain ruckus.com