Importing Digital Certificates and RSA Private Key Files

To allow a client to communicate with another RUCKUS ICX device using an SSL connection, you must configure a set of digital certificates and RSA public-private key pairs on the device. A digital certificate is used to identify the connecting client to the server. The certificate contains information about the issuing Certificate Authority as well as a public key. You can import digital certificates and private keys from a server.

Note: RUCKUS ICX devices support a maximum of 10 intermediate CA's for PKI or SSL authentication, excluding the ROOT CA.

If you choose to import an RSA certificate and private key file, you can use TFTP or SCP to transfer the files.

The following example copies the client certificate "client_cert.pem" from the TFTP server at IP address 10.1.1.1 to the ICX file "ssl-client-cert".

ICX# copy tftp flash 10.1.1.1 client_cert.pem  ssl-client-cert

The following example copies the client private key file "client_cert.pem" from the TFTP server to the ICX file "ssl-client-private-key".

ICX# copy tftp flash 10.1.1.1 client_cert.pem  ssl-client-private-key

The following example copies the root, or trusted, certificate "root_cert.pem" from the TFTP server to the ICX target file "ssl-trust-cert".

ICX# copy tftp flash 10.1.1.1 root_cert.pem ssl-trust-cert 

The following examples provide SCP alternative commands for copying the client certificate, private key, and root certificates.

The following example uses SCP to copy the client certificate from the remote SCP server at IP address 10.1.1.1.

ICX# copy scp flash 10.1.1.1 client_cert.pem  ssl-client-cert

The following example uses SCP to copy the client private key file from the remote server.

ICX# copy scp flash 10.1.1.1 client_cert.key.pem  ssl-client-private-key

The following example uses SCP to copy the root, or trusted, certificate from the remote server.

ICX# copy scp flash 10.1.1.1 root_cert.pem ssl-trust-cert