Configuring an SSL Profile for a TLS Connection
Configure an SSL profile for use with logging
and RADIUS Server hosts for NDcPP.
You must configure an SSL profile, to be applied to the RADIUS server, for use in establishing a secure TLS connection. The SSL profile specifies the root (CA) certificate trustpoint and the remote domain name to be used in certification.
- Name the SSL profile and enter profile configuration mode.
- Specify the trustpoint (CA server) that will be associated with the profile.
- Configure the remote domain name that the FQDN of the remote network peer certificate
issues to the server. This is the 'reference identifier' that must appear in the network
peer's certificate.
Note: The ICX device expects the 'reference identifier' value to be either in CN, or, if SAN is present, this value must be shown as a DNS name in the SAN.Note: The remote domain name must match the CN or SAN. ICX devices do not support wildcard bits in SAN extensions.
- (Optional) Use the
show ip ssl profilecommand to check the user SSL profile and device SSL profile information.
The following example configures the SSL profile tls01 and associates it with the trustpoint TLS-ABCD with ruckus.com as the remote domain name that the end user certificate issues to the server.
device# configure terminal device(config)# ip ssl profile tls01 device(config-ssl-tls01)# trustpoint TLS-ABCD device(config-ssl-tls01)# remotedomain ruckus.com
These statements were previously for ICX 7450 and ICX 7250 switches, both of which are deprecated in 10.0.00 as well as 10.0.10d, the release level in preparation for FIPS/CC as well as the security guide. I am retaining the text only in a draft comment temporarily, in case the FIPS/CC external tester wants to retrieve a partial statement about certification for some other reason. Otherwise, they should be permanently removed.