
Chapter 3: System planning
Security planning
Page 3-59
Item
Description
Quntity required
Root CA Public
Certificate
The self-signed public key certificate for the Root
CA that signed the Device Certificate in the
remote ODU.
The Root CA must form a certificate chain with
the Device Certificate without intermediate
certificates.
Normally one per
network.
TLS-PSK
Select the key size for the pre-shared key. This must be supported by AES licenses at each end
of the link.
TLS-PSK can be used with Access Method of Link Access, Link Name Access and Group
Access.
Ensure that the following cryptographic material is available.
Table 74 Pre-shared Key for wireless encryption
Item
Description
Quntity required
Wireless Link
Encryption Key
for AES
An encryption key generated using a
cryptographic key generator. The key length is
dictated by the selected AES encryption
algorithm (128 or 256 bits).
One per link. The same
encryption key is
required at each link end.
Planning for HTTPS/TLS operation
Before starting to configure HTTPS/TLS operation, ensure that the cryptographic material listed
in
Table 75 HTTPS/TLS security material
Item
Description
Quantity required
TLS Private Key
and Public
Certificates
An RSA private key of size 2048 bits, generated
in either PKCS#1 or PKCS#5 format,
unencrypted, and encoded in the ASN.1 DER
format.
An X.509 certificate containing a 2048-bit RSA
public key, signed using SHA-256, generated in
either PKCS#1 or PKCS#5 format, unencrypted,
and encoded in the ASN.1 DER format.
The public key certificate must have Common
Name equal to the IPv4 or IPv6 address of the
ODU.
The public key certificate must form a valid pair
with the private key.
Two pairs per link. These
items are unique to IP
address.
Содержание PTP 670 Series
Страница 1: ...F Cambium PTP 670 Series User Guide System Release 670 02 50 ...
Страница 349: ...Chapter 5 Installation Installing an SFP Ethernet interface Page 5 52 Correct Incorrect ...
Страница 405: ...Chapter 6 Configuration and alignment System menu Page 6 46 Figure 151 LAN Configuration page PTP topology TDM support ...
Страница 406: ...Chapter 6 Configuration and alignment System menu Page 6 47 Figure 152 LAN Configuration page PTP topology SFP support ...
Страница 408: ...Chapter 6 Configuration and alignment System menu Page 6 49 Figure 154 LAN Configuration page HCMP topology ...
Страница 416: ...Chapter 6 Configuration and alignment System menu Page 6 57 Figure 156 QoS Configuration page IP MPLS ...
Страница 445: ...Chapter 6 Configuration and alignment Management menu Page 6 86 Figure 173 Time Configuration page SNTP enabled ...
Страница 551: ...Chapter 7 Operation System statistics Page 7 64 Figure 250 Main Port Counters page when main port is bridging traffic ...