RDL-3000
FAMILY
USER MANUAL
70-00158-03-00
Proprietary Redline Communications © 2015
Page
161
of 254
April 17, 2015
c. Use the show command to verify the key file has been created:
show files usr
For example:
show files usr
...
ecc_keypairT.ecc
size=161
md5=f821c0c21ac9a2809140600832bf9340
2.
Generate ECDSA certificate.
The certificate request must be processed by Redline. Transmit each certificate
request file to your local Redline representative for processing.
Processed files returned will use the naming convention
ecc_resp_xx-xx-xx-xx-xx-
xx.rsp where, xx-xx-xx-xx-xx-xx is the MAC address of the wireless terminal.
3.
Upload the response file to the wireless terminal
Use a TFTP server to load the response file for each wireless terminal.
a. Copy the response file to the tftp transmit folder.
b. Login to the CLI interface of the terminal with the corresponding MAC address
and use the load command to upload and process each .rsp file:
load file <tftp_server_ip> ecc_resp_xx-xx-xx-xx-xx-xx.rsp usr tftp
c. Use the show command to necessary files are loaded:
show files usr
For example:
show files usr
...
ecc_keypairT.ecc
size=161
md5=f821c0c21ac9a2809140600832bf9340
ecc_keypair.ecc
size=161
md5=f821c0c21ac9a2809140600832bf9340
ecc_cert.ecc
size=454
md5=d6ca2942fc8fef9a89d300beafe692e6
d. Reboot the unit to activate the new credentials.
4.
Enable ECDSA authentication for the sector
Remote Terminals
a. Install ECDSA enabled options key
b. Open Configuration->Security screen and check (
)
enc AUTO MODE enable
Sector Controller
a. Install ECDSA enabled options key
6.4
SSH for Secure CLI
Wireless authentication is an optional purchased feature enabled by the options key.
SSH provides secure access when using the command line interface (CLI). Use an SSH
client such as OpenSSH or Putty to access the radio. When SSH is enabled, unsecure
methods (TELNET and HTTP) should be disabled.
Out-of-Box Operation
SSH is disabled by (factory) default and is activated by installing an options key that is
enabled for SSH. For out-of-box operation, a temporary DSA key is self-generated on
reboot. The operator can create a permanent key using the self-generate feature or load
an externally generated key (both operations disable the self-renewing key function).