Specifications
Certificates Automatically Generated by MSS
RoamAbout Mobility System Software Configuration Guide 16-5
Certificates Automatically Generated by MSS
ThefirsttimeyoubootaswitchwithMSSVersion4.2orlater,MSSautomaticallygenerateskeys
andself‐sig nedcertificates,incaseswherecertificatesarenotalreadyconfiguredorins talled.MSS
canautomaticallygenerateallthefollowingtypesofcertificatesandtheirkeys:
•Admin(requiredforadministrativeaccesstothe
switchbyWebVieworRoamAboutSwitch
Manager)
•EAP(requiredfor802.1Xuseraccessthroughtheswitch)
•Web(requiredforWebAAAuseraccessthroughtheswitch)
Thekeysare512byteslong.
MSSautomaticallygeneratesself‐signedcertificatesonlyincaseswherenocertificateisalready
configured.MSSdoesnotreplaceself‐signed
certificatesorCA‐signedcertificatesthatarealready
configuredontheswitch.Youcanreplaceanautomaticallygeneratedcertificatebycreating
anotherself‐signedoneorbyinstallingaCA‐signedone.Tousealongerkey,configurethekey
beforecreatingthenewcertificate(orcertificaterequest,ifyou
plantoinstallaCA‐signed
certificate).
IfgeneratedbyMSSVersion4.2.3orlater,theautomaticallygeneratedcertificatesare validfor
threeyears,beginningoneweekbeforetheti me anddateontheswitchwhenthecertificateis
generated.
Creating Keys and Certificates
Public‐privatekeypairsanddigitalcertificatesarerequiredformanagementaccesswith RASMor
WebView,orfornetworkaccessby802.1XorWebAAAusers.Thedigitalcertificatescanbeself‐
signedorsignedbyacertificateauthority(CA).IfyouusecertificatessignedbyaCA,youmust
also
installacertificatefromtheCAtovalidatethedigitalsignaturesofthecertificatesinstalledon
theRoamAboutswitch.
Generally,CA‐generatedcertificatesarevalidforoneyearbeginningwiththesystemtimeand
datethatareineffectwhenyougeneratethecertificaterequest.Self‐signedcertificatesgenerated
when
runningMSSVersion4.2.3orlaterarevalidforthreeyears,beginningoneweekbeforethe
timeanddateontheswitchwhenthecertificateisgenerated.
Eachofthefollowingtypesofaccessrequiresaseparatekeypairandcertificate:
• Admin—AdministrativeaccessthroughRoamAboutSwitchManagerorWebView
• EAP—802.1Xaccess
fornetworkuserswhocanaccessSSIDsencryptedbyWEPorWPA,and
forusersconnectedtowiredauthenticationports
• WebAAA—Webaccessfornetworkuserswhocanuseawebpagetologontoanunencrypted
SSID
ManagementaccesstotheCLIthroughSecureShell(SSH)alsorequiresakeypair,but
doesnot
useacertificate.(FormoreSSHinformation,see“ManagingSSH”onpage 5‐9.)
RoamAboutSwitchtoRoamAboutSwitchsecurityalsorequiresakeypairandcertificate.
However,thecertificateisgeneratedautomaticallywhenyouenableRBT‐RBTsecurity.