Creating A Certificate For Onboard Radius Authentication - Extreme Networks Altitude 4700 Series Product Reference Manual

Software version 4.1
Hide thumbs Also See for Altitude 4700 Series:
Table of Contents

Advertisement

Creating a Certificate for Onboard Radius Authentication

The access point can use its on-board RADIUS Server to generate certificates to authenticate MUs for
use with the Access Point. In addition, a Windows 2000 or 2003 Server is used to sign the certificate
before downloading it back to the Access Point's on-board RADIUS server and loading the certificate
for use with the Access Point.
Both a CA and Self certificate are required for Onboard RADIUS Authentication. For information on CA
Certificates, see
"Importing a CA Certificate" on page
format or risk loading an invalid certificate.
CAUTION
If using the RADIUS time-based authentication feature to authenticate Access Point user permissions,
ensure the Access Point's time is synchronized with the CA server used to generate certificate requests.
CAUTION
Self certificates can only be generated using the Access Point GUI and CLI interfaces. No functionality
exists for creating a self-certificate using the Access Point's SNMP configuration option.
To create a self certificate for on-board RADIUS authentication:
1 Select System Configuration > Certificate Mgmt > Self Certificates from the access point menu tree.
2 Click on the Add button to create the certificate request.
The Certificate Request screen displays.
3 Complete the request form with the pertinent information.
Key ID (required)
Subject (required)
Department
Organization
City
State
Postal Code
Country Code
Email
Altitude 4700 Series Access Point Product Reference Guide
Enter a logical name for the certificate to help distinguish
between certificates. The name can be up to 7 characters
in length.
The required Subject value contains important information
about the certificate. Contact the CA signing the certificate
to determine the content of the Subject parameter.
Optionally enter a value for your organizations's
department name if needing to differentiate the certificate
from similar certificates used in other departments within
your organization.
Optionally enter the name of your organization for
supporting information for the certificate request.
Optionally enter the name of the City where the Access
Point (using the certificate) resides.
Optionally enter the name of the State where the Access
Point (using the certificate) resides.
Optionally enter the name of the Postal (Zip) Code where
the Access Point (using the certificate) resides.
Optionally enter the Access Point's Country Code.
Enter an organizational email address (avoid using a
personal address if possible) to associate the request with
the proper requesting organization.
91. Ensure the certificate is in a Base 64 Encoded
95

Advertisement

Table of Contents
loading

Table of Contents