&
User
AN-80i
Manual
70-00072-01-08b
Proprietary Redline Communications © 2009
Page 107 of 128
June 4, 2009
Chapter
7
7
7
S
S
e
e
c
c
u
u
r
r
i
i
t
t
y
y
K
K
e
e
y
y
s
s
a
a
n
n
d
d
C
C
e
e
r
r
t
t
i
i
f
f
i
i
c
c
a
a
t
t
e
e
s
s
7.1 Wireless
Authentication
Beginning with v3.09-PTP and 11.20-PMP, the AN-80i wireless security feature includes
AN-80i node level authentication based on X.509 certificates.
7.1.1 Using X.509 Certificates
Authentication can be enabled and disabled using CLI commands (set x509auth on/off)
or the HTTP Web interface (X.509 Authentication Enable field in the Configure System
screen). To user the authentication feature, an RSA key file and X.509 certificate file
must be loaded on the AN-80i unit.
Factory X.509 Certificates and Keys
An-80i units field upgraded to v3.09-PTP/11.20-PMP or higher will not have an X.509
certificate and private key in the factory table. Use the CLI command 'files factory' to
view the factory table and determine if the certificate and key file exist.
When the factory files are not present, user-generated certificate and key files must be
loaded before enabling the authentication feature. See
Loading User-Defined
Certificates and Keys
following for details.
Note: Units manfactured with v3.09-PTP/11.20-PMP (or higher) software may include a
pre-installed X.509 certificate and private key saved in the factory (fact) table. The
validating authority certificate and can not be displayed or modified.
Loading User-Defined Certificates and Keys
The user may create an authority and generate an RSA key and certificate files (unit
certificate and authority certificate) using an external application. The public RSA key
should be 1024 or 2048 bits and the hash algorithm should be SHA1 or SHA256. The
subject of the unit certificate must conform to the following format: AN80I-aa-bb-cc-dd-
ee-ff, where aa-bb-cc-dd-ee-ff is the unit MAC address.
Important: Always use secure transfer and storage when working with
encryption keys and certificates. Store encryption keys and certificate
information in a secure location. It is recommended to use the local Ethernet
port when loading encryption keys and certificates on the AN-80i.
The maximum file size for a wireless certificate is 1400 bytes. User-defined key files
must conform to the filename format specified in the CLI 'load' command. All files are
verified at each reboot.
When X.509 Authentication is enabled, the user (usr) files have the highest priority.
Factory (fact) files are used when there are no files in the user table.
The private key and certificate must be loaded using the CLI 'load' command.
Example: Download certificates and key file (from a user certificate authority) for the unit
with the MAC address: '00 09 02 01 C1 9A':