<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Install a Certificate on SZ/vSZ? in RUCKUS Self-Help</title>
    <link>https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/How-to-Install-a-Certificate-on-SZ-vSZ/m-p/79799#M360</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Do we have to make any DNS entries after uploading the public certificate which is going to be used for guest portal under AP Portal menu mapping?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 16 May 2024 11:19:09 GMT</pubDate>
    <dc:creator>nilesh_kahar</dc:creator>
    <dc:date>2024-05-16T11:19:09Z</dc:date>
    <item>
      <title>How to Install a Certificate on SZ/vSZ?</title>
      <link>https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/How-to-Install-a-Certificate-on-SZ-vSZ/m-p/45407#M12</link>
      <description>&lt;P&gt;How to Install a Certificate on SZ/vSZ?&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Generate the CSR from any node, or the same can be generated from a third part device:&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;System &amp;gt;&amp;gt; Certificates &amp;gt;&amp;gt; CSR &amp;gt;&amp;gt; Generate&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="remya_murugesh_0-1656526482177.png" style="width: 498px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/2815i50288EC29836E4BF/image-dimensions/498x178/is-moderation-mode/true?v=v2" width="498" height="178" role="button" title="remya_murugesh_0-1656526482177.png" alt="remya_murugesh_0-1656526482177.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Fill in the details and submit the same to a CA authority&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="remya_murugesh_1-1656526482182.png" style="width: 400px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/2816i16C6070E0596A500/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="remya_murugesh_1-1656526482182.png" alt="remya_murugesh_1-1656526482182.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;Now, you will be able to see the same CSR in all nodes in the cluster&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Once the certificate is received, import the certificate to SZ from System &amp;gt;&amp;gt; Certificates &amp;gt;&amp;gt;&amp;nbsp; SZ as a Server Cert&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;Browse and select the Server, Intermediate and Root certificates accordingly for the intended certificate&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;Alternatively, you may chain all the related certificates to a single file in .pem format and map the same against Server Certificate&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;Chaining order: Server, Intermediate and Root&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Apply Private Key&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;Select the CSR associated with the certificate for private key&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;For a third party generated CSR, upload the private key along with the associated certificates&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;Note: The certificate formats supported are only PEM and CRT&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Click on the Validate certificate and Click OK once the validate summary is displayed&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="remya_murugesh_2-1656526482186.png" style="width: 509px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/2817iCD1D9309A506C9CE/image-dimensions/509x286/is-moderation-mode/true?v=v2" width="509" height="286" role="button" title="remya_murugesh_2-1656526482186.png" alt="remya_murugesh_2-1656526482186.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;Once the certificate is successfully uploaded, you can again crosscheck the certificate availability on each node in cluster&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Then the certificate can be mapped against the preferred services from System &amp;gt;&amp;gt; Certificates &amp;gt;&amp;gt; Certificate to Service Mapping&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="remya_murugesh_3-1656526482188.png" style="width: 501px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/2818i7ABC5B7799BA579F/image-dimensions/501x197/is-moderation-mode/true?v=v2" width="501" height="197" role="button" title="remya_murugesh_3-1656526482188.png" alt="remya_murugesh_3-1656526482188.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Management Web : Used by Web UI and Public API traffic&lt;/LI&gt;
&lt;LI&gt;AP Portal: Used by Web Auth WLAN and Guest Access WLAN control traffic&lt;/LI&gt;
&lt;LI&gt;Hostpot Wispr: Used by WISPr WLAN control (Northbound Interface, Captive Portal, and Internal Subscriber Portal) traffic&lt;/LI&gt;
&lt;LI&gt;Ruckus Intra device: Used by AP control traffic&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;This will again be synced among the cluster nodes.&lt;/P&gt;
&lt;P&gt;Please note that the certificate import would initiate a service restart on the web and subscriber management applications. You can verify the status of the services from SZ CLI:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&amp;gt;&lt;FONT face="courier new,courier"&gt;en&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier"&gt;&amp;lt;enable password&amp;gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier"&gt;#show service&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 10:44:18 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/How-to-Install-a-Certificate-on-SZ-vSZ/m-p/45407#M12</guid>
      <dc:creator>remya_murugesh</dc:creator>
      <dc:date>2022-09-21T10:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to Install a Certificate on SZ/vSZ?</title>
      <link>https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/How-to-Install-a-Certificate-on-SZ-vSZ/m-p/46879#M55</link>
      <description>&lt;P&gt;Very useful clarification, documentation isn't describing this important task in detail. I think it is important to mention that certificate should be a wildcard certificate, as the same certificate is used on all vSZ or SZ nodes in a cluster, so it must be valid for multiple FQDNs.&lt;/P&gt;&lt;P&gt;Therefore the cheapest certificate will not do&amp;nbsp; -- except if you can use FQDN for one node as&amp;nbsp;domain.com and for another -- &lt;A href="http://www.domain.com" target="_blank"&gt;www.domain.com&lt;/A&gt;&amp;nbsp;, this will work as by default most certificates include both names. You can import simple one-domain certificate, but than you will be able connect securely to only one node, to the second node you'll need to connect only using IP and will be getting warning in a browser - modern browser don't allow connection by name to site with wrong certificate...&amp;nbsp;&lt;/P&gt;&lt;P&gt;Services restart after certificate change can easy take 30 minutes, so don't be warried that you broke the system.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 17:33:44 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/How-to-Install-a-Certificate-on-SZ-vSZ/m-p/46879#M55</guid>
      <dc:creator>eizens_putnins</dc:creator>
      <dc:date>2022-10-13T17:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to Install a Certificate on SZ/vSZ?</title>
      <link>https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/How-to-Install-a-Certificate-on-SZ-vSZ/m-p/79795#M359</link>
      <description>&lt;P&gt;Do we have to make any DNS entries after uploading the public certificate which is going to be used for guest portal under AP Portal menu mapping?&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2024 07:21:49 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/How-to-Install-a-Certificate-on-SZ-vSZ/m-p/79795#M359</guid>
      <dc:creator>nilesh_kahar</dc:creator>
      <dc:date>2024-05-16T07:21:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to Install a Certificate on SZ/vSZ?</title>
      <link>https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/How-to-Install-a-Certificate-on-SZ-vSZ/m-p/79799#M360</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Do we have to make any DNS entries after uploading the public certificate which is going to be used for guest portal under AP Portal menu mapping?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2024 11:19:09 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/How-to-Install-a-Certificate-on-SZ-vSZ/m-p/79799#M360</guid>
      <dc:creator>nilesh_kahar</dc:creator>
      <dc:date>2024-05-16T11:19:09Z</dc:date>
    </item>
  </channel>
</rss>

