Setting up SSL encryption for controller connections
By default, a connection to the controller uses SSL encryption. To set up SSL encryption, copy the SSL certificate and SSL client private key from the remote machine where you generated them into the device's flash using the following commands:
device(config)# copy tftp flash <remote ip> <remote file> client-certificate device(config)# copy tftp flash <remote ip> <remote file> client-private-key
The IP address specifies the remote machine from which the SSL client certificate
is being copied. The file name specifies the client certificate in the
copy tftp flash client-certificate command, and the client private key in the
copy tftp flast client-private-key command.
The
remote file variable specifies the file name of the client certificate in the first command,
and the client private key in the second command.
For each controller, you must enter both the commands. The device can store up to three SSL certificates and client private keys. If you remove a controller connection, you must delete the SSL certificates and client private keys from the device’s flash memory using the monitor mode commands.