Importing Digital Certificates and RSA Private Key Files
To allow a client to communicate with another RUCKUS ICX device using an SSL connection, you must configure a set of digital certificates and RSA public-private key pairs on the device. A digital certificate is used to identify the connecting client to the server. The certificate contains information about the issuing Certificate Authority as well as a public key. You can import digital certificates and private keys from a server, or you can allow the RUCKUS ICX device to create them.
If you want to allow the RUCKUS ICX device to create the digital certificates, refer to Generating an SSL certificate. If you choose to import an RSA certificate and private key file from a client, you can use TFTP to transfer the files.
ip ssl certificate-data-file tftp command followed by the IP address of the TFTP server and the filename of the certificate
as shown in the following example.
device# configure terminal device(config)# ip ssl certificate-data-file tftp 192.168.9.210 certfile
The example imports the certificate file named certfile from the TFTP server with the IP address 192.168.9.210.
To import an RSA private key from a client using TFTP, enter the
ip ssl private-key-file tftp command followed by the IP address of the TFTP server and the name of the key file
as shown in the following example.
device# configure terminal device(config)# ip ssl private-key-file tftp 192.168.9.210 keyfile
The example imports the private key file named keyfile from the TFTP server with the IP address 192.168.9.210.