User Guide for FibeAir® IP-20 All-Outdoor Products, CeraOS 10.5
Page 692 of 825
Ceragon Proprietary and Confidential
•
Eth Func Group Write level
–
The Write access level in the Eth functional
group: None, Regular or Advanced.
•
Sync Func Group Read level
–
The Read access level in the Sync functional
group: None, Regular or Advanced.
•
Sync Func Group Write level
–
The Write access level in the Sync functional
group: None, Regular or Advanced.
21.5
Configuring X.509 CSR Certificates and HTTPS (CLI)
The web interface protocol for accessing IP-20 can be configured to HTTP (default)
or HTTPS. It cannot be set to both at the same time.
Before setting the protocol to HTTPS, you must:
1 Create and upload a CSR file. See
Generating a Certificate Signing Request
2 Download the certificate to the IP-20 and install the certificate. See
Downloading a Certificate (CLI)
3 Enable HTTPS. See
When uploading a CSR and downloading a certificate, the IP-20 functions as an
SFTP client. You must install SFTP server software on the PC or laptop you are
using to perform the upload or download. For details, see
Configuring an FTP or SFTP Server
Note:
For these operations, SFTP must be used.
This section includes:
•
Generating a Certificate Signing Request (CSR) File (CLI)
•
Downloading a Certificate (CLI)
•
•
Generating a Certificate Signing Request (CSR) File (CLI)
To set the CSR parameters, enter the following command in root view:
root> platform security csr-set-parameters common-name <common-
name> country <country> state <state> locality <locality>
organization <organization> org-unit <org-unit> email <email>
file-format <file-format>
To display the currently-configured CSR parameters, enter the following command
in root view:
root> platform security csr-show-parameters
If the IP address family is configured to be IPv4, enter the following command in
root view to configure the SFTP server parameters for the CSR file upload:
root> platform security csr-set-server-parameters server-ipv4
<server-ipv4> server-path <server-path> filename <filename>
server-username <username> server-password <password>
If the IP address family is configured to be IPv6, enter the following command in
root view to configure the SFTP server parameters for the CSR file upload: