&
User
AN-80i
Manual
70-00072-01-07
Proprietary Redline Communications © 2010
Page 101 of 106
Sept 18, 2008
7.8
Security Keys and Certificates
The certificates and keys required by the cryptographic modules are saved in non-
volatile memory. The certificates and keys are checked and loaded at each reboot. User
(usr) settings take precedence over factory (factory) settings. The following table lists the
methods for using CLI to configure operation with SSH or SSL.
Using SSH
When the software is first upgraded, the SSH 'usr' fields for DSA and RSA are blank.
The operator may download a customer-defined RSA and DSA key pair, or use the
'generate' command to create keys locally on the AN-80i. Note that customer-defined
key files must conform to the filename format described in Table 66: Security -- User Key
and Certificate Files.
For example, the DSA key file for AN-80i with MAC address 00-09-02-00-
01-02 may be named: dsa_key_00-09-02-00-01-02.pem.
Using SSL (TLS)
When the software is first upgraded, the SSL 'usr' fields are blank. The operator may
download a customer-defined RSA and DSA key pair, or use the default (embedded)
certificate and private key (identical for all AN-80i units). Note that customer-defined
certificate and key files must conform to the filename format described in Table 66:
Security -- User Key and Certificate Files.
For example, SSL certificate file for AN-80i with
MAC address 00-09-02-00-01-02 may be named: ssl_cert_00-09-02-00-01-02.pem.
Table 64: Security -- Keys and Certificates
Feature
Parameters
Field Upgrade
Factory 3.00 Unit
(Future)
SSH:
Secure
CLI
dsa_key_<mac>.pe
m
rsa_key<mac>.pem.
1. Use 'generate' command to
create RSA and DSA key pair
locally on AN-80i and save in
'usr' settings.
--- or ---
2. Use 'load' command to save
customer-defined RSA and
DSA key pair in 'usr' settings.
(1) and (2) as in field
upgrade plus:
3. Factory supplied RSA
and DSA key pair may be
pre-loaded into factory
settings for out-of-box
SSH functionality.
SSL:
Secure
Web
ssl_cert<mac>.pem
ssl_key<mac>.pem
1. Use the default (embedded)
certificate and private key.
--- or ---
2. Use 'load' command to save
customer-defined certificate and
private key in 'usr' settings.
(1) and (2) as in field
upgrade.
Note: Use the 'minus' character to delimit the MAC address.