20
M
ANAGING
K
EYS
AND
C
ERTIFICATES
A digital certificate is a form of electronic identification for computers.
The WX switch requires digital certificates to authenticate its
communications to 3Com Wireless Switch Manager and Web Manager,
to WebAAA clients, and to Extensible Authentication Protocol (EAP)
clients for which the WX performs all EAP processing. Certificates can be
generated on the WX or obtained from a certificate authority (CA). Keys
contained within the certificates allow the WX, its servers, and its wireless
clients to exchange information secured by encryption.
If the switch does not already have certificates, MSS automatically
generates the missing ones the first time you boot using MSS Version 4.2
or later. You do not need to install certificates unless you want to replace
the ones automatically generated by MSS. (For more information, see
“Certificates Automatically Generated by MSS” on page 418.)
Before installing a new certificate, verify with the
display timedate
and
display
timezone
commands that the WX switch is set to the correct
date, time, and time zone. Otherwise, certificates might not be installed
correctly.
Why Use Keys and
Certificates?
Certain WX switch operations require the use of public-private key pairs
and digital certificates. All 3Com Wireless Switch Manager and Web
Manager users, and users for which the WX performs IEEE 802.1X EAP
authentication or WebAAA, require public-private key pairs and digital
certificates to be installed on the WX switch.
These keys and certificates are fundamental to securing wireless, wired
authentication, and administrative connections because they support
Wi-Fi Protected Access (WPA) encryption and dynamic Wired-Equivalency
Privacy (WEP) encryption.
Summary of Contents for 3CRWX120695A
Page 138: ...138 CHAPTER 6 CONFIGURING AND MANAGING IP INTERFACES AND SERVICES ...
Page 272: ...272 CHAPTER 11 CONFIGURING RF LOAD BALANCING FOR MAPS ...
Page 310: ...310 CHAPTER 13 CONFIGURING USER ENCRYPTION ...
Page 322: ...322 CHAPTER 14 CONFIGURING RF AUTO TUNING ...
Page 350: ...350 CHAPTER 16 CONFIGURING QUALITY OF SERVICE ...
Page 368: ...368 CHAPTER 17 CONFIGURING AND MANAGING SPANNING TREE PROTOCOL ...
Page 412: ...412 CHAPTER 19 CONFIGURING AND MANAGING SECURITY ACLS ...
Page 518: ...518 CHAPTER 21 CONFIGURING AAA FOR NETWORK USERS ...
Page 530: ...530 CHAPTER 22 CONFIGURING COMMUNICATION WITH RADIUS ...
Page 542: ...542 CHAPTER 23 MANAGING 802 1X ON THE WX SWITCH ...
Page 598: ...598 CHAPTER 26 ROGUE DETECTION AND COUNTERMEASURES ...
Page 706: ...706 GLOSSARY ...