Chapter 6
Security
RUGGEDCOM ROX II
CLI User Guide
144 Managing the Trusted Certificate Store
cgTpR3rCs4xTUh+URJYCTGEhh1V6jGOjuY8M3pO/iLPrwtZ066uyCqNoJLoptYnLfRDJu8AdWNdxLfXQsSv4XOB8hzYKekyg8bqsE/
w6b5MyE60Xc51f413PMicZz6WhBcuaqvutHxoIqCR6oI7fkLGGyWaeCzWUO02FplVfiJe1vTwAaa5+JAoSdPNzTJKrHvFE18SdEAlwpj4PMVIA7oaEHL9vb"
Section6.8.2
Managing the Trusted Certificate Store
The Trusted Certificate Store includes an extensive collection of publically available X.509 v3 root certificates.
Once enabled and associated with one or more Certified Authorities (CAs), these certificates are available for all
HTTPS or FTPS operations.
For a list of root certificates included in the Trusted Certificate Store, refer to Section6.8.2.3, “List of Root
Certificates in the Trusted Certificate Store”.
NOTE
The Trusted Certificate Store is disabled by default.
NOTE
Custom certificates may be required for select features, such as IPsec tunnels. For more information
about adding, a custom certificate, refer to Section6.8.7.3, “Adding a Certificate”.
CONTENTS
• Section6.8.2.1, “Configuring the Trusted Certificate Store”
• Section6.8.2.2, “Enabling/Disabling the Trusted Certificate Store”
• Section6.8.2.3, “List of Root Certificates in the Trusted Certificate Store”
Section6.8.2.1
Configuring the Trusted Certificate Store
To configure the Trusted Certificate Store, do the following:
1. Make sure the required CA certificates and CRLs are configured. For more information, refer to
Section6.8.4.3, “Adding a CA Certificate and CRL”.
2. Enable the Trusted Certificate Store. For more information, refer to Section6.8.2.2, “Enabling/Disabling the
Trusted Certificate Store”.
3. Add CA certificates to the Store to validate the authenticity of the root certificates. For more information,
refer to Section6.8.3.2, “Adding a CA Certificate to the Trusted Certificate Store”.
Section6.8.2.2
Enabling/Disabling the Trusted Certificate Store
To enable or disable the Trusted Certificate Store, do the following:
1. Make sure the CLI is in Configuration mode.
2. Enable or disable the Trusted Certificate Store by typing: