&
User
AN-80i
Manual
70-00072-01-08b
Proprietary Redline Communications © 2009
Page 109 of 128
June 4, 2009
Load SSH Key Files from a Server
The AN-80i can load DSA and RSA key files that have been created using an external
application. The RSA key should be a maximum of 4096 bits and the DSA key should be
a maximum of 2048 bits. The key file names must conform to the filename format
specified in the CLI 'load' command. All loaded files are verified at each reboot.
Example: Load DSA and RSA key files for the AN-80i unit with MAC address: '00 09 02
01 C1 9A'. The TFTP server address is 192.168.25.1.
192.168.25.2# load file 192.168.25.1 dsa_key_00-09-02-01-C1-9A.pem
192.168.25.2# load file 192.168.25.1 rsa_key_00-09-02-01-C1-9A.pem
192.168.25.2# reboot
The unit must be rebooted following any changes (load/del) to the user table files.
Table 50: Security -- SSH -- Factory and Software Upgrade
Feature
Parameters
Field Upgrade
Factory Installed)
SSH:
Secure
CLI
dsa_key_<mac>.pem
rsa_key<mac>.pem.
1. Use 'generate' command
to create RSA and DSA key
files locally and save in 'usr'
table.
--- or ---
2. Use 'load' command to
save externally generated
RSA and DSA key files in the
user table.
v3.09-PTP/11.20-PMP or
higher:
(1) and (2) as in field
upgrade plus:
3. Factory supplied RSA
and DSA key pair may be
pre-loaded into factory
settings for out-of-box SSH
functionality.
Important: Always use secure transfer and storage when working with
encryption keys and certificates. Store encryption keys and certificate
information in a secure location. It is recommended to use the local Ethernet
port when loading encryption keys and certificates on the AN-80i.
7.2.2 Using SSL (HTTPS) for Secure Web Access
Starting with v3.09-PTP/11.20-PMP, the AN-80i wireless security feature includes SSL
(HTTPS) for secure Web access. This feature can be enabled and disabled using the
'HTTPS Enable' field on the Web interface.
SSL Embedded Certificate and Key
The SSH feature requires an X.509 certificate and RSA key file (PEM format) to be
present on the AN-80i unit.
AN-80i units field upgraded to v3.09-PTP/11.20-PMP (or higher) will have an embedded
X.509 certificate and RSA key (same for all units). This provides out-of-the-box use of
the HTTPS feature. The embedded authority certificate can not be displayed or changed
by the user.
Note: Units manfactured with v3.09-PTP/11.20-PMP (or higher) software may include a
pre-installed X.509 certificate and private key saved in the factory (fact) table. The
validating authority certificate and can not be displayed or modified.