MSM7xx Controllers Configuration Guide v6.4.0
Trusted CA certificate store
This list displays all root CA (certificate authority) certificates installed on the controller. The controller
uses these CA certificates to validate the certificates supplied by peers during authentication.
Multiple CA certificates can be installed to support validation of clients with certificates issued by
different CAs.
The controller uses these certificates to validate certificates supplied by:
• Managers or operators accessing the controller's management tool.
• HTML users accessing the public access interface.
• SOAP clients communicating with the controller's SOAP server.
• RADIUS EAP
The following information is presented for each certificate in the list:
• Status light: Indicates the certificate state.
Green: Certificate is valid.◦
◦ Yellow: Certificate will expire soon.
◦ Red: Certificate has expired.
• ID: A sequentially assigned number to help identify certificates with the same common name.
• Issued to: Name of the certificate holder. Select the name to view the contents of the certificate.
• Issued by: Name of the CA that issued the certificate.
• Current usage: Lists the services that are currently using this certificate.
• Start/Expiration date: Indicates the period during which the certificate is valid.
• CRL: Indicates if a certificate revocation list is bound to the certificate. An X.509 certificate
revocation list is a document produced by a certificate authority (CA) that provides a list of
serial numbers of certificate that have been signed by the CA but that should be rejected.
• Delete: Select to remove the certificate from the certificate store.
Installing a new CA certificate
1. Specify the name of the certificate file or select Browse to choose from a list. CA certificates
must be in X.509 or PKCS #7 format.
2. Select Install to install a new CA certificate.
Managing certificates 377










