User Guide

Table Of Contents
379
Nortel WLAN Security Switch 2300 Series Configuration Guide
Managing Keys and
Certificates
A digital certificate is a form of electronic identification for computers. The WSS switch requires digital certificates to
authenticate its communications to WLAN Management Software and Web View, to Web-based AAA clients, and to
Extensible Authentication Protocol (EAP) clients for which the WSS performs all EAP processing. Certificates can be
generated on the WSS or obtained from a certificate authority (CA). Keys contained within the certificates allow the
WSS, its servers, and its wireless clients to exchange information secured by encryption.
Why Use Keys and Certificates?
Certain WSS switch operations require the use of public-private key pairs and digital certificates. All WLAN Manage-
ment Software and Web View users, and users for which the WSS performs IEEE 802.1X EAP authentication or
Web-based AAA, require public-private key pairs and digital certificates to be installed on the WSS switch.
These keys and certificates are fundamental to securing wireless, wired authentication, and administrative connections
because they support Wi-Fi Protected Access (WPA) encryption and dynamic Wired-Equivalency Privacy (WEP)
encryption.
Why Use Keys and Certificates? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 379
About Keys and Certificates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 381
Creating Keys and Certificates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 385
Displaying Certificate and Key Information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 393
Key and Certificate Configuration Scenarios . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 393
Note. Before installing a certificate, verify with the show timedate and show timezone
commands that the WSS switch is set to the correct date, time, and time zone. Otherwise,
certificates might not be installed correctly.