How-To: Create a RadSec Client Certificate in Keytos Shield

Learn how to create a RadSec Client certificate in Keytos Shield, allowing you to connect your network to Shield securely via RadSec.

Overview - What is a RadSec Client Certificate?

When a network access point or switch connects to Keytos Shield via RadSec (RADIUS over TLS), it needs to present a client certificate that Keytos Shield can trust and validate. Some network devices, such as Cisco Meraki, use a certificate issued by the vendor’s own CA. However, for other network devices such as Unifi, you will need to install a RadSec client certificate that you created in Keytos Shield. This guide will go over creating a RadSec client certificate in Keytos Shield for RadSec authentication with your network controller.

Step-by-Step Guide - How to Issue RadSec Client Certificates in Keytos Shield

Follow these steps to create and issue a RadSec client certificate in Keytos Shield.

Prerequisites for Creating RadSec Client Certificates in Keytos Shield

Before you begin creating RadSec client certificates in Keytos Shield, ensure that you have completed all the necessary prerequisites:

  1. The Keytos Entra ID applications are registered in your tenant.
  2. You have signed up for a Keytos Shield Plan.
  3. You are a Subscription Owner or Network Administrator.
  4. You have completed the Keytos Shield Network Security onboarding

How to Create a Keytos Shield RadSec Client Certificate

  1. Navigate to the Keytos Shield Network profiles page from the left-hand menu.

  2. At the top of the page, select the Settings tab.

    Keytos Shield Network Profiles page with Settings tab highlighted
  3. Scroll down to the bottom of the page and expand the Create Certificate section.

    Keytos Shield Network Profiles page with Create Certificate section highlighted
  4. For What type of certificate do you want to create? select RadSec.

    Keytos Shield Network Profiles page with RadSec button highlighted
  5. For the Private key, either select Generate Locally or Import CSR depending on your use case.

    • If you select Generate Locally, Keytos Shield will generate the private key for the certificate in your browser and then issue the RadSec client certificate. The private key never leaves the browser and you can download both the certificate and the private key.
    • If you select Import CSR, you will need to provide a Certificate Signing Request (CSR) from your network device for Keytos Shield to issue the RadSec client certificate. Click How to Create a CSR for guidance on generating a CSR from your device.
  6. Click Create certificate.

    Keytos Shield Network Profiles Page with create RadSec client certificate button highlighted
  7. Once the certificate has been created, click Download Certificate and Download Private Key (if applicable). These should download as radsec.cer and radsec.key, respectively.

    Keytos Shield Network Profiles Page with download RadSec client certificate and private key button highlighted
  8. Done! You should have created a RadSec client certificate that you can upload to your networking device for RadSec authentication.