ip ssl

Configures Secure Socket Layer (SSL) settings.
Syntax
ip ssl cert-key-size size
no ip ssl cert-key-size size
ip ssl port port-num
no ip ssl port port-num
Command Default

I think at least the cert-key-size may go away entirely, although the 2048 option only was listed as deprecated. I also think the entire ip ssl command *may* need to be deprecated, as the only unmentioned options are for port designation and for a single key size, while the default key size option is not even available.
The default key size for RUCKUS-issued and imported digital certificates is 2048 bits.

By default, SSL protocol exchanges occur on TCP port 443.

Parameters
cert-key-size size
Configures SSL server certificate key size. Valid value is 4096.
ipv4-address
Configures the IPv4 address of the TFTP server from which the certificates are imported.
ipv6 ipv6-address
Configures the IPv6 address of the TFTP server from which the certificates are imported.
file-name
The certificate data or key file name.
port port-num
Specifies the HTTPS/SSL port. The default port is 443.
Modes

Global configuration mode

Usage Guidelines

The SSL server certificate key size applies only to digital certificates issued by RUCKUS and does not apply to imported certificates.

To allow a client to communicate with another RUCKUS device using an SSL connection, you configure a set of digital certificates and RSA public-private key pairs on the device. A digital certificate is used for identifying the connecting client to the server. It contains information about the issuing Certificate Authority (CA) as well as a public key. You can import digital certificates and private keys from a server, or you can allow the device to create them. The RSA private key can be up to 4096 bits.

The no form of the command removes the configurations.

Examples

The following example shows how to change the port number used for SSL communication.

device# configure terminal
device(config)# ip ssl port 334

The following example shows how to configure the SSL certificate generation signing request for a country.

device# configure terminal
device(config)# ip ssl certificate country us
History
Release version Command history
09.0.00 The following command options were deprecated and replaced by new or existing copy ttftp flash command options: ip ssl certificate-data-file tftp, ip ssl certificate common-name, ip ssl certificate country, ip ssl certificate locality, ip ssl certificate org, ip ssl certificate org-unit, ip ssl certificate state, ip ssl cert-key-size 2048, ip ssl client-certificate tftp, ip ssl client-privae-key tftp, and ip ssl private-key-file tftp