Certificate and Key Backup and Recovery Mechanism in a Deployed AP
The following section explains the backup
and recovery mechanism used in the RUCKUS NOR Certificate Safe Storage (RNCSS)
feature.
- After a firmware image is upgraded on a deployed AP and during the first bootup, the AP stores and validates the certificate and key to the NOR memory region. If the validation fails, the certificate and key is backed up to the NOR memory region. On every reboot, the certificate and key is validated in the NAND or eMMC, and in the NOR copy.
- If the certificate or key, or
both, is corrupted or lost, they are recovered using the following RNCSS
recovery procedure:
- The RNCSS recovery validates the NOR memory's header by verifying the checksum of the header. If the checksum fails, the data bytes count is verified, else the certificate's NOR memory is dumped.
- The AP MAC address and serial number from the NOR memory are compared with the current AP MAC address and serial number, and their values are logged into the syslog server. In case of a mismatch, an event is triggered to the controller.
- In case the certificate and key is corrupted, the backup stored in the NOR memory region is used and their storage locations are logged in to the syslog and the support log.
- The type, length, value
(TLV) attributes are parsed and their checksum is validated. The parsed
files are stored in a temporary location; the Trusted Platform Module
(TPM) APs
system.datais stored only in the TPM directory. - Upon successful verification of the certificate and key, they are stored in the mount point. The temporary files are erased and the bootup sequence is continued.
- If the verification fails with a header mismatch error, then the NOR memory may be corrupted. If the verification fails with a certificate or key error, then the certificate or key region in the NOR memory may be corrupted.