![Redline RDL-3000 SC Скачать руководство пользователя страница 127](http://html.mh-extra.com/html/redline/rdl-3000-sc/rdl-3000-sc_user-manual_1429320127.webp)
RDL-3000
User Manual
70-00158-01-DRAFT
Proprietary Redline Communications © 2010
Page
127
of 142
November 25, 2010
Stream cipher cannot be reverse-engineered -- even by destroying the equipment
Key generation algorithm cannot be reverse-engineered -- even by destroying the
equipment
MAC address of a system cannot be changed without damaging the equipment
Two communicating RDL-3000 systems detecting they have the same MAC address
will immediately shut down
Important Security Guidelines
:
1.
Store encryption keys and certificate information in a secure location.
2.
Always use secure transfer (e.g., SSH or SSL) when working with encryption keys
and certificates.
3.
It is recommended to use the RDL-3000 local Ethernet port to transfer encryption
keys and certificates, or sftp if loading certificates or keys across an open network.
7.2
Wireless Authentication
Wireless authentication is a standard feature on all RDL-3000 systems.
7.2.1
Out-of-Box Operation
Wireless authentication is not supported out of box. Each RDL-3000 system to use
wireless authentication must meet the following requirements:
1. The operator must generate and load X.509 certificate and key files
2. The wireless certificate and key files must be loaded into the user (usr) table. The
files can only be loaded using the CLI interface (Telnet or SSH). Reboot the RDL-
3000 to activate the certificate and key.
3. Configure and activate authentication services.
7.2.2
Generate X.509 Certificate and Key Files
Use a commercially available tool to create the required X.509 certificates and keys.
The filenames used must comply with the following requirements:
usr_wacert_<mac>.der
X.509 authority certificate
usr_wcert_<mac>.der
X.509 certificate
usr_wkey_<mac>.der
Private key
7.2.3
Load Wireless X.509 Certificate and Key Files
Use the following steps to setup wireless authentication:
1. Copy the certificate and key files to the default directory of a TFTP server.
2. Use the Command 'load' to copy the certificate and key files from the TFTP server to
the RDL-3000.
3. Use the command 'show files usr' to verify the files have been successfully loaded.
4. Reboot the RDL-3000 to activate changes.
7.2.4
Enable Authentication
The wireless X.509 certificate and key files must be loaded into the usr table and the
RDL-3000 rebooted to activate the new keys before wireless authentication can be
enabled.
Use one of the following methods to enable authentication:
CLI:
set x509auth on