
2-5
Cisco Wireless LAN Controller Configuration Guide
OL-13826-01
Chapter 2 Using the Web-Browser and CLI Interfaces
Using the Web-Browser Interface
Loading an Externally Generated SSL Certificate
You can use a TFTP server to download an externally generated SSL certificate to the controller. Follow
these guidelines for using TFTP:
• If you load the certificate through the service port, the TFTP server must be on the same subnet as
the controller because the service port is not routable, or you must create static routes on the
controller. Also, if you load the certificate through the distribution system network port, the TFTP
server can be on any subnet.
• A third-party TFTP server cannot run on the same computer as the Cisco WCS because the WCS
built-in TFTP server and the third-party TFTP server require the same communication port.
Note Every HTTPS certificate contains an embedded RSA key. The length of the key can vary from 512 bits,
which is relatively insecure, to thousands of bits, which is very secure. When you obtain a new certificate
from a Certificate Authority, make sure that the RSA key embedded in the certificate is at least 768 bits
long.
Using the GUI to Load an SSL Certificate
Follow these steps to load an externally generated SSL certificate using the controller GUI.
Step 1 On the HTTP Configuration page, check the Download SSL Certificate check box (see Figure 2-2).
Figure 2-2 HTTP Configuration Page
Step 2
In the Server IP Address field, enter the IP address of the TFTP server.
Step 3 In the Maximum Retries field, enter the maximum number of times that the TFTP server attempts to
download the certificate.
Step 4 In the Timeout field, enter the amount of time (in seconds) that the TFTP server attempts to download
the certificate.
Step 5 In the Certificate File Path field, enter the directory path of the certificate.
Comentários a estes Manuais