6 - 69
Certificates
Note: Refer to the Security Primer (available at www.honeywellaidc.com) to prepare the Authentication Server and Access Point
for communication.
Note: It is important that all dates are correct on the Marathon and host computers when using any type of certificate. Certificates
are date sensitive and if the date is not correct authentication will fail.
Quick Start
Root Certificates are necessary for EAP-TLS, PEAP/GTC and PEAP/MSCHAP.
1. Generate a Root CA Certificate either from the Marathon or using a PC. See Generating a Root CA Certificate (page 6-69)
2. If a PC was used to request the certificate, copy the certificate to the Marathon.
3. Install the Root CA Certificate. See Installing a Root CA Certificate (page 6-71).
User Certificates are necessary for EAP-TLS.
1. Generate a User Certificate either from the Marathon or using a PC. See Generating a User Certificate (page 6-72).
2. If a PC was used to request the certificate, copy the certificate to the Marathon.
3. Install the User Certificate. See Installing a User Certificate (page 6-76).
4. Verify installation.
Generating a Root CA Certificate
Note: It is important that all dates are correct on the Marathon and host computers when using any type of certificate.
Certificates are date sensitive and if the date is not correct authentication will fail.
The easiest way to get the root CA certificate is to use a browser on a PC to navigate to the Certificate Authority. To request
the root CA certificate, open a browser to http://<CA IP address>/certserv.
Note: It may be necessary to use a PC to request the certificate for Windows 7 Professional devices.
The Marathon can be used to generate the certificate instead of a PC.
Sign into the CA with any valid user name and password.
If using the Windows Certificate Store, the Windows Account must have a password. The password cannot be left
blank. The Summit Client Utility uses the Windows user account credentials to access the Certificate Store. The
Windows user account credentials need not be the same as the wireless credentials entered in the Summit Client
Utility.