ip ssl
ip ssl
cert-key-size
size
no ip ssl
cert-key-size
size
ip ssl
{
certificate-data-file
|
client-certificate
|
client-private-key
|
private-key-file
}
tftp
{
ipv4-address
|
ipv6
ipv6-address}
file-name
no ip ssl
{
certificate-data-file
|
client-certificate
|
client-private-key
|
private-key-file
}
tftp
{
ipv4-address
|
ipv6
ipv6-address}
file-name
ip ssl
port
port-num
no ip ssl
port
port-num
ip ssl
certificate
{
common-name
|
country
|
locality
|
org
|
org-unit
|
state
}
name
no ip ssl
certificate
{
common-name
|
country
|
locality
|
org
|
org-unit
|
state
}
name
The default key size for RUCKUS-issued and imported digital certificates is 2048 bits.
By default, SSL protocol exchanges occur on TCP port 443.
The default TFTP server is not configured.
- ipv4-address
- Configures the IPv4 address of the TFTP server from which the certificates are imported.
- ipv6 ipv6-address
- Configures the IPv6 address of the TFTP server from which the certificates are imported.
- certificate
- Configures the SSL certificate generation signing request.
- common-name
-
Specifies the common name, fully qualified domain name, or web address for which you plan to use your certificate.
- name
- Fully qualified domain name or web address for which you plan to use your certificate (for example, www.server.com) when used with common-name, two letter code country name (for example, US) when used with country, locality name (for example, city) when used with locality, organization name (for example, company) when used with org, organization unit name (for example, section) when used with org-unit, or province name (for example, California) when used with state.
Global configuration mode
The SSL server certificate key size applies only to digital certificates issued by RUCKUS and does not apply to imported certificates.
To allow a client to communicate with another RUCKUS device using an SSL connection, you configure a set of digital certificates and RSA public-private key pairs on the device. A digital certificate is used for identifying the connecting client to the server. It contains information about the issuing Certificate Authority (CA) as well as a public key. You can import digital certificates and private keys from a server, or you can allow the device to create them. The RSA private key can be up to 4096 bits.
The following example shows how to import a digital certificate issued by a third-party Certificate Authority (CA) and save it in the flash memory.
device# configure terminal device(config)# ip ssl certificate-data-file tftp 10.10.10.1 cacert.pem
The following example shows how to change the key size for RUCKUS-issued and imported digital certificates to 4096 bits.
device# configure terminal device(config)# ip ssl cert-key-size 4096
The following example shows how to change the port number used for SSL communication.
device# configure terminal device(config)# ip ssl port 334
The following example shows how to import an RSA private key from a client.
device# configure terminal device(config)# ip ssl private-key-file tftp 192.168.9.210 keyfile