Wireless/Redundant Edge Services xl Module Management and Configuration Guide WS.02.xx and greater

Table Of Contents
2-167
Configuring the ProCurve Wireless Edge Services xl Module
Digital Certificates
Configuring Digital Certificates
On the Wireless Edge Services xl Module, you create and manage trustpoints,
in which you create or load the following elements:
Server certificate, which is the certificate that identifies and authenticates
the module
For a self-signed certificate, you create the server certificate yourself and
have the Wireless Edge Services xl Module sign it. Otherwise, you create
a certificate request, which you submit to a CA. After the CA returns the
certificate, you install it on the module as a server certificate.
Part of creating a certificate or certificate request is generating the public/
private key pair.
CA certificate, which is the certificate of the CA that issues the server
certificate
This certificate is not necessary if the server certificate is self-signed.
Otherwise, however, you must load the CA certificate before or at the
same time that you load the server certificate.
CRL
This element is optional, but recommended to prevent your module from
accepting invalid certificates. Your CA should provide you with a CRL.
You must complete these tasks to configure a self-signed certificate:
1. Optionally, pre-create a specific key for the certificate. Typically, however,
you can allow the module to automatically generate a key when you create
the certificate.
2. Use the Certificates Wizard to create the certificate.
You must complete these tasks to install a server certificate signed by a CA:
1. Optionally, pre-create a specific key for the certificate. Typically, however,
the module can automatically generate a key when you create the certif-
icate request.
2. Use the Certificates Wizard to create the certificate request.
3. Submit the certificate request to your CA.
4. The CA will generate the server certificate and send it to you. It should
also send the CA certificate and a CRL. Load these files on an FTP server,
a TFTP server, or the station that runs the Web browser interface.
5. Use the Certificates Wizard to upload the server certificate and CA certif-
icate.