DataPlane validates SmartZone

DataPlane validates the incoming SmartZone certificate to check if the certificate is valid.
When the Dataplane discovers SmartZone for the first time, Dataplane validates if the SmartZone has the same certificate. If the certificates match then the connection is establishes otherwise it is terminated.

To upload the certificate, perform the below steps:

DataPlane Setup script
  1. Import the DataPlane setup script and upload the certificate in SZone Trusted CACerts/Chain (DP).

    Upload DataPlane Certificate

  2. Copy the entire trusted cert content including the "-----BEGIN CERTIFICATE-----" and "-----END CERTIFICATE-----".

    Setup Upload Certificate

  3. After the setup process, users should be able to enable the server validation via the DataPlane CLI.
    The upload command is enable->config→controller→set_trust_chain
    • For vDP the upload command is show dp_root_ca. The root CA is generated in the location /etc/dp_config/discover and use this root CA to sign a client cert for vDP TLS connection.
    • For physical DP, it should use the MIC cert to do TLS connection. The certificate should pass the validation with Ruckus root CA.