RUGGEDCOM RSG2488
User Guide
Chapter 1
Introduction
Key Files
3
• Configuration files are provided in the CSV (comma separated values) format for ease of use. Make sure that
configuration files are properly protected when they exist outside of the device. For instance, encrypt the files,
store them in a secure place, and do not transfer them via insecure communication channels.
• Management of the configuration file, certificates and keys is the responsibility of the device owner. Before
returning the device to RuggedCom for repair, make sure encryption is disabled (to create a cleartext version of
the configuration file) and replace the current certificates and keys with temporary certificates and keys that can
be destroyed upon the device's return.
Section 1.2.2
Key Files
ROS uses security keys to establish secure remote logins (SSH) and Web access (SSL).
It is strongly recommended that a unique SSL certificate and SSH keys be created and provisioned. New ROS-
based units from RuggedCom will be shipped with a unique certificate and keys preconfigured in the
ssl.crt
and
ssh.keys
flash files.
The default and auto-generated SSL certificates are self-signed. It is recommended to use an SSL certificate that
is either signed by a trusted third-party Certificate Authority (CA) or by an organization's own CA. This technique
is described in the RuggedCom application note:
Creating/Uploading SSH Keys and SSL Certificates to ROS
Using Windows
, available from
.
The sequence of events related to Key Management during an upgrade to ROS 4.0 or later is as follows:
NOTE
The auto-generation of SSH keys is not available for Non-Controlled (NC) versions of ROS.
• On first boot, ROS will start the SSH and SSL services using the
default keys
.
• Immediately after boot, ROS will start to generate a unique SSL certificate and SSH key pair, and save each
one to its corresponding flash file. This process will take only a few minutes to complete on a lightly loaded unit.
As each one is created, the corresponding service is immediately restarted with the new keys.
• At any time during the key generation process, custom keys can be uploaded. The custom keys will take
precedence over both the default and auto-generated keys.
• On subsequent boot, if there is a valid
ssl.crt
file, the default certificate will not be used for SSL. If there is a
valid
ssh.keys
file, the default SSH key will not be used.
• At any time, new keys may be uploaded or generated by ROS using the
sslkeygen
or
sshkeygen
CLI
commands.
The following sections describe SSL certificates and SSH key pairs in more detail:
•
Section 1.2.2.1, “SSL Certificates”
•
Section 1.2.2.2, “SSH Key Pairs”
Section 1.2.2.1
SSL Certificates
ROS supports SSL certificates that conform to the following specifications:
• X.509 v3 digital certificate format
• PEM format
Содержание RSG2488
Страница 1: ...Rugged Operating System ROS v4 0 User Guide RUGGEDCOM RSG2488 April 5 2013 www RuggedCom com ...
Страница 12: ...Preface RUGGEDCOM RSG2488 User Guide xii Customer Support ...
Страница 36: ...Chapter 1 Introduction RUGGEDCOM RSG2488 User Guide 24 Removable Memory ...
Страница 190: ...Chapter 5 Setup and Configuration RUGGEDCOM RSG2488 User Guide 178 Viewing Statistics for LLDP Ports ...