Specifications

Certificates Automatically Generated by MSS
RoamAbout Mobility System Software Configuration Guide 16-5
Certificates Automatically Generated by MSS
ThefirsttimeyoubootaswitchwithMSSVersion4.2orlater,MSSautomaticallygenerateskeys
andselfsig nedcertificates,incaseswherecertificatesarenotalreadyconfiguredorins talled.MSS
canautomaticallygenerateallthefollowingtypesofcertificatesandtheirkeys:
•Admin(requiredforadministrativeaccesstothe
switchbyWebVieworRoamAboutSwitch
Manager)
•EAP(requiredfor802.1Xuseraccessthroughtheswitch)
•Web(requiredforWebAAAuseraccessthroughtheswitch)
Thekeysare512byteslong.
MSSautomaticallygeneratesselfsignedcertificatesonlyincaseswherenocertificateisalready
configured.MSSdoesnotreplaceselfsigned
certificatesorCAsignedcertificatesthatarealready
configuredontheswitch.Youcanreplaceanautomaticallygeneratedcertificatebycreating
anotherselfsignedoneorbyinstallingaCAsignedone.Tousealongerkey,configurethekey
beforecreatingthenewcertificate(orcertificaterequest,ifyou
plantoinstallaCAsigned
certificate).
IfgeneratedbyMSSVersion4.2.3orlater,theautomaticallygeneratedcertificatesare validfor
threeyears,beginningoneweekbeforetheti me anddateontheswitchwhenthecertificateis
generated.
Creating Keys and Certificates
Publicprivatekeypairsanddigitalcertificatesarerequiredformanagementaccesswith RASMor
WebView,orfornetworkaccessby802.1XorWebAAAusers.Thedigitalcertificatescanbeself
signedorsignedbyacertificateauthority(CA).IfyouusecertificatessignedbyaCA,youmust
also
installacertificatefromtheCAtovalidatethedigitalsignaturesofthecertificatesinstalledon
theRoamAboutswitch.
Generally,CAgeneratedcertificatesarevalidforoneyearbeginningwiththesystemtimeand
datethatareineffectwhenyougeneratethecertificaterequest.Selfsignedcertificatesgenerated
when
runningMSSVersion4.2.3orlaterarevalidforthreeyears,beginningoneweekbeforethe
timeanddateontheswitchwhenthecertificateisgenerated.
Eachofthefollowingtypesofaccessrequiresaseparatekeypairandcertificate:
Admin—AdministrativeaccessthroughRoamAboutSwitchManagerorWebView
EAP—802.1Xaccess
fornetworkuserswhocanaccessSSIDsencryptedbyWEPorWPA,and
forusersconnectedtowiredauthenticationports
WebAAA—Webaccessfornetworkuserswhocanuseawebpagetologontoanunencrypted
SSID
ManagementaccesstotheCLIthroughSecureShell(SSH)alsorequiresakeypair,but
doesnot
useacertificate.(FormoreSSHinformation,seeManagingSSHonpage 59.)
RoamAboutSwitchtoRoamAboutSwitchsecurityalsorequiresakeypairandcertificate.
However,thecertificateisgeneratedautomaticallywhenyouenableRBTRBTsecurity.