Configuring an SSL Profile for Use with RADIUS Server Hosts

You must configure an SSL profile, to be applied to the RADIUS server, for use in establishing a secure TLS connection. The SSL profile specifies the root (CA) certificate trustpoint and the remote domain name to be used in certification.

Note: On ICX 7250 and ICX 7450 series switches, the device trustpoint will not work with RADIUS due to the strict validation of certification. For TLS with RADIUS on these switches, an external certificate must be copied to the ICX device in order to establish a successful TLS session. Refer to ICX Digital Certificates for more information.

  1. Name the SSL profile and enter profile configuration mode.
    device# configure terminal
    device(config)# ip ssl profile tls01
    
  2. Specify the trustpoint (CA server) that will be associated with the profile.
    device(config-ssl-tls01)# trustpoint TLS-ABCD
    
  3. Configure the remote domain name that the FQDN of the remote network peer certificate issues to the server. This is the 'reference identifier' that must appear in the network peer's certificate.
    Note: The ICX device expects the 'reference identifier' value to be either in CN, or, if SAN is present, this value must be shown as a DNS name in the SAN.
    Note: The remote domain name must match the CN or SAN. ICX devices do not support wildcard bits in SAN extensions.
    device(config-ssl-tls01)# remotedomain ruckus.com
    device(config-ssl-tls01)# exit
    device(config)#
  4. (Optional) Use the show ip ssl profile command to check the user SSL profile and device SSL profile information.

The following example configures the SSL profile tls01 and associates it with the trustpoint TLS-ABCD with ruckus.com as the remote domain name that the end user certificate issues to the server.

device# configure terminal
device(config)# ip ssl profile tls01
device(config-ssl-tls01)# trustpoint TLS-ABCD
device(config-ssl-tls01)# remotedomain ruckus.com