Configuring an SSL Profile for Use with Logging and RADIUS Server Hosts for NDcPP
Before configuring a server host, you must configure an SSL profile.
- Name the SSL profile and enter profile configuration mode.
- Specify the trustpoint (CA server) that will be associated with the profile.
- Configure the remote domain name that the FQDN of the remote network peer certificate
issues to the server. This is the 'reference identifier' that must appear in the network
peer's certificate.
Note: The FastIron device expects the 'reference identifier' value to be either in CN, or, if SAN is present, this value must be shown as a DNS name in the SAN.
The following example configures the SSL profile tls01 and associates it with the trustpoint TLS-ABCD with ruckus.com as the remote domain name that the end user certificate issues to the server.
device# configure terminal device(config)# ip ssl profile tls01 device(config-ssl-tls01)# trustpoint TLS-ABCD device(config-ssl-tls01)# remotedomain ruckus.com