Generating a Certificate

You can create certificates to establish secure communication and verify the identity of an entity in your network.

A certificate template must exist before you begin this procedure. Refer to Adding a Certificate Template for instructions.
Complete the following steps to generate a certificate:
  1. From the navigation bar, select Network Control > Service Catalog.
    The Service Catalog page is displayed.
  2. Find the Certificate Management tile and click Add.
    The Add Certificate Instance page is displayed.
  3. Select Device Certificate from the options under Template Instance Type and select Certificate from the options under Device Certificate Type, then click Next.
    The Generate Certificate page is displayed.
    Generating Certificate
  4. On the Generate Certificate page, complete the following:
    Note: The generated certificate uses the Common Name configuration defined in the selected certificate template. The values specified in the certificate request fields are used to replace the corresponding variables in the template during certificate generation.
    • Certificate Template: Select a certificate template from the drop-down. The selected certificate template defines the certificate authority, certificate attributes, and certificate properties.
    • Identity: Click Select Identity, and select an identity from the Associate Identity sidebar.

      If an Identity is not yet defined, you can create a new one; click Add Identity, complete the fields in the Create Identity sidebar, and click Apply. You can then select the newly created identity from the Identity drop-down. Refer to Adding an Identity for more details.

    • CSR Source: Select one of the following options:
      • Auto-Generate CSR: Automatically generates the certificate signing request.
      • Copy & Paste CSR: Allows you to enter an existing certificate signing request.
    • Certificate Signing Request: Enter or paste the certificate signing request.
      Note: The Certificate Signing Request field is displayed only when Copy & Paste CSR is selected.
    • Description: Enter a description.
  5. Click Generate.
    The certificate is generated and displayed on the Certificates sub-tab under Device Certificates.
    The Certificates sub-tab displays the following information:
    • Common Name: Displays the common name of the certificate holder.
    • Status: Displays the status of the certificate: Valid, Revoked, or Expired.
    • Expiration Date: Displays the expiration date.
    • CA Name: Displays the name of the certificate authority.
    • Template: Displays the name of the certificate template.
    • Revocation Date: Displays the revocation date.
    • Identity: Displays the identity associated with the certificate. Click the identity name to open the identity details page.
    • Issued By: Displays the certificate issuer.
    • Timestamp: Displays the timestamp.
    • Serial Number: Displays the serial number.
    • Thumbprint: Displays the certificate thumbprint.
    • Email: Displays the email address associated with the certificate.

    You can customize which fields appear in the table by clicking the icon and selecting or deselecting the desired column names. Drag and drop individual column names up or down the list to customize the left‑to‑right column display in the table. Optionally, you can click Reset to default to have the default subset of columns appear in the table. Use the Clear Filters option to remove all applied filters.

    You can use the Search option to display only the table entries matching the specified common name; enter a minimum of two characters. Additionally, you can filter the list by selecting an option from the Status drop-down list.

  6. (Optional) On the Certificates sub-tab, click the common name of a certificate to view the certificate details.
    The Certificate Details sidebar is displayed, containing the following expandable sections:
    • Certificate Information
    • Download
    • Usage
    Viewing Certificate Details
  7. (Optional) Expand Certificate Information to view the following certificate details:
    • Common Name: Displays the common name associated with the certificate.
    • Status: Displays the current certificate status.
    • Valid Not Before: Displays the date before which the certificate is not valid.
    • Valid Not After: Displays the date after which the certificate is no longer valid.
    • Organization: Displays the organization associated with the certificate.
    • Organization Unit: Displays the organizational unit associated with the certificate.
    • Locality: Displays the locality associated with the certificate.
    • State: Displays the state associated with the certificate.
    • Country: Displays the country associated with the certificate.
    • Serial Number: Displays the certificate serial number.
    • Key Length: Displays the certificate key length.
    • Key Usage: Displays the permitted uses of the certificate key.
    • SHA Fingerprint: Displays the SHA fingerprint of the certificate.
    • Certificate Template: Displays the certificate template used to generate the certificate.
    • Certificate Authority: Displays the certificate authority that issued the certificate.
    • Identity: Displays the identity associated with the certificate. Click the identity name to open the identity details page.
    • Description: Displays the certificate description.

    To view the certificate, click View Certificate.

  8. (Optional) Expand Download to view or download certificate data:
    • Public Key: Provides the following options:
      • View Public Key: Displays the public key.
      • Download PEM: Downloads the public key in PEM format.
      • Download DER: Downloads the public key in DER format.
    • Chain: Provides the following options:
      • View Chain: Displays the certificate chain.
      • Download PEM: Downloads the certificate chain in PEM format.
      • Download PKCS7: Downloads the certificate chain in PKCS7 format.

      A certificate-chain PEM file contains the complete chain of trust, including the end-entity certificate, intermediate certificates, and the root certificate.

      Note: For an AAA Authentication RadSec profile, ensure that the certificate chain includes all intermediate certificates up to the trusted root CA. The server certificate must be signed by a CA in the configured trust chain to establish a TLS session.
    • Private Key: Provides the following options:
      • View Private Key: Displays the private key.
      • Download: Downloads the private key. Enter a password to encrypt the downloaded file.
    • P12 Format: Provides the following options:
      • Download Without Chain: Downloads the P12 certificate package without the certificate chain.
      • Download With Chain: Downloads the P12 certificate package with the certificate chain. This option is commonly used for client devices.
      Enter a password to encrypt the downloaded P12 file.
  9. (Optional) Expand Usage.
    The Usage section displays the following information:
    • Issued: Displays the date and time the certificate was issued.
    • Last RADIUS Policy: Displays the last RADIUS policy that used the certificate.
    Note: For EAP-based authentication, clients can use the Domain Suffix Match setting to validate the DNS name contained in the server certificate.
    • Value: ruckus.cloud
    • Purpose: Validates the EAP server certificate by its DNS name during EAP authentication.
    • Validation Rule: The configured value must match a dNSName entry in the certificate's subjectAltName extension. Multiple values can be specified by separating them with semicolons (;). The certificate is considered valid if at least one value matches.
    • Limitation: Wildcards are not supported. For example, example.com matches server.example.com but does not match server-example.com.
    • Availability: This setting is available only for EAP connections.
  10. (Optional) Select the checkbox alongside a certificate name to display the following management options:
    • Revoke: Blocks a certificate from being used for authentication.
    • Unrevoke: Restores a revoked certificate to a valid status.
    • Delete: Permanently removes a certificate record.