Setting Up SSL Encryption for Controller Connections

By default, a connection to the controller uses SSL encryption. To set up SSL encryption, copy the SSL certificate and SSL client private key from the remote machine where you generated them into the device's flash memory using the copy tftp flash client-certificate and copy tftp flash client-private-key commands.

device# copy tftp flash 10.176.6.93 clientcert client-certificate
device# copy tftp flash 10.176.6.93 rsakey client-private-key

The IP address in the command specifies the remote machine from which the SSL client certificate is being copied. The file name specifies the client certificate in the copy tftp flash client-certificate command, and the client private key in the copy tftp flash client-private-key command.

Note: SSL is not supported on passive controller connections.

For each controller, you must enter both the commands. The device can store up to three SSL certificates and client private keys. If you remove a controller connection, you must delete the SSL certificates and client private keys from the device’s flash memory using the Privileged EXEC mode commands.

Note: When using SSL to connect to the switch, the OpenFlow Controller can send only 50 flows at a time (for typical flows). This is not applicable to TCP-only connections to the OpenFlow Controller.