18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 14: Configuring Virtual Private Networks<br />

Configuring Certificate Management<br />

About the Remote<br />

Certificates tab<br />

Adding a remote<br />

certificate<br />

428<br />

The Remote Certificates tab enables you to view the list <strong>of</strong> available remote<br />

certificates. These certificates represent the potential peers with which<br />

<strong>Sidewinder</strong> <strong>G2</strong> can establish a VPN connection. To display the properties <strong>of</strong> a<br />

specific certificate, select the certificate from within the list. Its properties are<br />

displayed on the right portion <strong>of</strong> the window. For a description <strong>of</strong> these<br />

properties, see “Adding a remote certificate”.<br />

Note: You cannot modify the properties <strong>of</strong> a certificate from this window. To modify<br />

a certificate you must delete it and then add it back using the new properties.<br />

From this window, you can perform the following actions:<br />

• Add a new certificate to the Certificate list—Click New and see “Adding a<br />

remote certificate” on page 428 for details.<br />

• Delete a certificate from the list—Select the certificate you want to delete<br />

and click Delete.<br />

• Import certificates—Click Import and see “Importing a remote certificate”<br />

on page 434.<br />

• Export certificates—Click Export and see “Exporting remote or firewall<br />

certificates” on page 435.<br />

• Query the CA for Certificate status—If a certificate request has been<br />

submitted to be signed by a CA, click the Query button to query the CA to<br />

see if the certificate is approved. If yes, the Status field will change to<br />

SIGNED and the approved certificate will be retrieved.<br />

If the certificate request is Manual PKCS10, click the Load button to query<br />

and retrieve the signed certificate.<br />

Note: By default, Netscape CAs and CAs that support the Simple Certificate<br />

Enrollment Protocol (SCEP) are checked every 15 minutes for any certificates<br />

waiting to be signed.<br />

The Create New Remote Certificate window enables you to add a certificate to<br />

the Remote Certificate list. To add a remote certificate, follow the steps below.<br />

Note: The default certificate key size is 1024 bits. The default lifetime for selfsigned<br />

certificates created on the <strong>Sidewinder</strong> <strong>G2</strong> is five years.<br />

1 In the Certificate Name field, type a name for this certificate.<br />

2 In the Distinguished Name field, create a distinguished name. See<br />

“Understanding Distinguished Name syntax” on page 416 for information on<br />

the format that should be used. Note the following:<br />

• The order <strong>of</strong> the specified distinguished name fields must match the<br />

order listed in the certificate.<br />

• Some CAs will not support the optional identity types specified in step 3<br />

through step 5.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!