Specifications

About Keys and Certificates
RoamAbout Mobility System Software Configuration Guide 16-3
•IftheRoamAboutswitchhasaselfsignedcertificateinitscertificateandkeystore,theswitch
respondstotherequestfromMSS.Ifthecertificateisnotselfsigned,theswitchlooksfora
CAscertificatewithwhichtovalidatetheservercertificate.
•IftheRoamAboutswitchhasnocorresponding
CAcertificate,theswitchdoesnotrespondto
therequestfromMSS.IftheswitchdoeshaveacorrespondingCAcertificate,andtheserver
certificateisvalidated(datestillvalid,signatureapproved),theswitchresponds.
IftheRoamAboutswitchdoesnotrespondtotherequestfromMSS,authenticationfailsand
access
isdenied.
ForEAP(802.1X)users,thepublicprivatekeypairsanddigitalcertificatescanbestoredona
RADIUSserver.Inthiscase,theR oamAboutswitchoperatesasapassthrough authenticator.
Public Key Infrastructures
Apublickeyinfrastructure(PKI)isasystemof digitalcertificatesandcertificationauthoritiesthat
verifyandauthenticatethevalidityofeach partyinvolvedinatransactionthroughtheuseof
publickeycryptography.TohaveaPKI,theRoamAboutswitchrequiresthefollowing:
•Apublickey
•Aprivatekey
Digitalcertificates
•A
CA
•Asecureplacetostoretheprivatekey
APKIenablesyoutosecurelyexchangeandvalidatedigitalcertificatesbetweenRoamAbout
switches,servers,anduserssothateachdevicecanauthenticateitselftotheothers.
Public and Private Keys
Enterasys Network’sidentitybasednetworkingusespublickeycryptographytoenforcethe
privacyofdatatransmittedoverthenetwork.Usingpublicprivatekeypairs,usersanddevices
cansendencryptedmessagesthatonlytheintendedreceivercandecrypt.
Beforeexchangingmessages,eachpartyinatransactioncreatesakeypairthatincludes
thepublic
andprivatekeys.Thepublickeyencryptsdataandverifiesdigitalsignatures,andthe
correspondingprivatekeydecryptsdataandgeneratesdigitalsignatures.Publickeysarefreely
exchangedaspartofdigitalcertificates.Privatekeysare storedsecurely.
Digital Certificates
Digitalcertificatesbindtheidentityofnetworkusersanddevicestoapublickey.Networkusers
mustauthenticatetheiridentitytothosewithwhomtheycommunicate,andmustbeabletoverify
theidentityofotherusersandnetworkdevices,suchasswitchesandRADIUSservers.
TheEnterasys NetworksMobilitySystemsupports
thefollow ingtypesofX.509digital certificates:
Administrativecertificate—UsedbytheRoamAboutswitchtoauthenticateitselfto
RoamAboutSwitchManagerorWebView.
RoamAboutSwitchtoRoamAboutSwitchsecuritycertificate—UsedbyRoamAbout
SwitchesinaMobilityDomaintosecurelyexchangemanagementinformation.(Formore