Configuring an SSL Profile for a TLS Connection

Configure an SSL profile for use with logging and RADIUS Server hosts for NDcPP.

You must configure an SSL profile, to be applied to the RADIUS server, for use in establishing a secure TLS connection. The SSL profile specifies the root (CA) certificate trustpoint and the remote domain name to be used in certification.

These statements were previously for ICX 7450 and ICX 7250 switches, both of which are deprecated in 10.0.00 as well as 10.0.10d, the release level in preparation for FIPS/CC as well as the security guide. I am retaining the text only in a draft comment temporarily, in case the FIPS/CC external tester wants to retrieve a partial statement about certification for some other reason. Otherwise, they should be permanently removed.

Note: On ICX 7250 series switches, the device trustpoint will not work with RADIUS due to the strict validation of certification. For TLS with RADIUS on these switches, an external certificate must be copied to the ICX device in order to establish a successful TLS session.

  1. Name the SSL profile and enter profile configuration mode.
    device# configure terminal
    device(config)# ip ssl profile tls01
    
    Syntax: ip ssl profile profile-name
    Syntax: no ip ssl profile profile-name
  2. Specify the trustpoint (CA server) that will be associated with the profile.
    device(config-ssl-tls01)# trustpoint TLS-ABCD
    
    Syntax: trustpoint trustpoint-name
    Syntax: no trustpoint trustpoint-name
  3. Configure the remote domain name that the FQDN of the remote network peer certificate issues to the server. This is the 'reference identifier' that must appear in the network peer's certificate.
    Note: The ICX device expects the 'reference identifier' value to be either in CN, or, if SAN is present, this value must be shown as a DNS name in the SAN.
    Note: The remote domain name must match the CN or SAN. ICX devices do not support wildcard bits in SAN extensions.
    device(config-ssl-tls01)# remotedomain ruckus.com
    device(config-ssl-tls01)# exit
    device(config)#
    Syntax: remotedomain domain-name
    Syntax: no remotedomain domain-name
  4. (Optional) Use the show ip ssl profile command to check the user SSL profile and device SSL profile information.

The following example configures the SSL profile tls01 and associates it with the trustpoint TLS-ABCD with ruckus.com as the remote domain name that the end user certificate issues to the server.

device# configure terminal
device(config)# ip ssl profile tls01
device(config-ssl-tls01)# trustpoint TLS-ABCD
device(config-ssl-tls01)# remotedomain ruckus.com