Specifications
About Keys and Certificates
RoamAbout Mobility System Software Configuration Guide 16-3
•IftheRoamAboutswitchhasaself‐signedcertificateinitscertificateandkeystore,theswitch
respondstotherequestfromMSS.Ifthecertificateisnotself‐signed,theswitchlooksfora
CA’scertificatewithwhichtovalidatetheservercertificate.
•IftheRoamAboutswitchhasnocorresponding
CAcertificate,theswitchdoesnotrespondto
therequestfromMSS.IftheswitchdoeshaveacorrespondingCAcertificate,andtheserver
certificateisvalidated(datestillvalid,signatureapproved),theswitchresponds.
IftheRoamAboutswitchdoesnotrespondtotherequestfromMSS,authenticationfailsand
access
isdenied.
ForEAP(802.1X)users,thepublic‐privatekeypairsanddigitalcertificatescanbestoredona
RADIUSserver.Inthiscase,theR oamAboutswitchoperatesasapass‐through authenticator.
Public Key Infrastructures
Apublic‐keyinfrastructure(PKI)isasystemof digitalcertificatesandcertificationauthoritiesthat
verifyandauthenticatethevalidityofeach partyinvolvedinatransactionthroughtheuseof
publickeycryptography.TohaveaPKI,theRoamAboutswitchrequiresthefollowing:
•Apublickey
•Aprivatekey
• Digitalcertificates
•A
CA
•Asecureplacetostoretheprivatekey
APKIenablesyoutosecurelyexchangeandvalidatedigitalcertificatesbetweenRoamAbout
switches,servers,anduserssothateachdevicecanauthenticateitselftotheothers.
Public and Private Keys
Enterasys Network’sidentity‐basednetworkingusespublickeycryptographytoenforcethe
privacyofdatatransmittedoverthenetwork.Usingpublic‐privatekeypairs,usersanddevices
cansendencryptedmessagesthatonlytheintendedreceivercandecrypt.
Beforeexchangingmessages,eachpartyinatransactioncreatesakeypairthatincludes
thepublic
andprivatekeys.Thepublickeyencryptsdataandverifiesdigitalsignatures,andthe
correspondingprivatekeydecryptsdataandgeneratesdigitalsignatures.Publickeysarefreely
exchangedaspartofdigitalcertificates.Privatekeysare storedsecurely.
Digital Certificates
Digitalcertificatesbindtheidentityofnetworkusersanddevicestoapublickey.Networkusers
mustauthenticatetheiridentitytothosewithwhomtheycommunicate,andmustbeabletoverify
theidentityofotherusersandnetworkdevices,suchasswitchesandRADIUSservers.
TheEnterasys NetworksMobilitySystemsupports
thefollow ingtypesofX.509digital certificates:
• Administrativecertificate—UsedbytheRoamAboutswitchtoauthenticateitselfto
RoamAboutSwitchManagerorWebView.
• RoamAboutSwitchtoRoamAboutSwitchsecuritycertificate—UsedbyRoamAbout
SwitchesinaMobilityDomaintosecurelyexchangemanagementinformation.(Formore