18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring Certificate Management<br />

13-38 Configuring Virtual Private Networks<br />

From this tab, you can perform the following actions:<br />

Note: You cannot modify the properties <strong>of</strong> a certificate from this window. To modify a<br />

certificate you must delete it and then add it back using the new properties.<br />

Add a firewall certificate—Click New to add a certificate to the<br />

Certificate list. See “Adding a firewall certificate” on page 13-38 for<br />

details.<br />

Delete a firewall certificate—Highlight the certificate and click Delete<br />

to remove the selected certificate from the Certificate list.<br />

Note: A certificate cannot be deleted if it is currently used by one or more areas (for<br />

example, Security Associations, Application Defenses, etc.).<br />

Import a firewall certificate—Click Import to import an existing<br />

certificate and its related private key file. See “Importing a firewall<br />

certificate” on page 13-46 for more information.<br />

Export a firewall certificate—Click Export to export the selected<br />

certificate to a file. The export function is generally used when<br />

capturing the certificate information needed by a remote partner<br />

such as a VPN client. See “Exporting remote or firewall certificates”<br />

on page 13-48 for more details.<br />

Retrieve a certificate—If a certificate request has been submitted to<br />

be signed by a CA, click the Query button to query the CA to see if<br />

the certificate is approved. If yes, the Status field will change to<br />

SIGNED and the approved certificate will be retrieved.<br />

If the certificate request is Manual PKCS10, click the Load button to<br />

load the signed certificate from a file supplied by the CA.<br />

Note: By default, Netscape CAs and CAs that support the Simple Certificate Enrollment<br />

Protocol (SCEP) are checked every 15 minutes for any certificates waiting to be signed.<br />

Adding a firewall certificate The Create New Firewall Certificate window enables you to add a<br />

certificate to the Firewall Certificate list. To add a certificate, follow the<br />

steps below.<br />

Note: The default certificate key size is 1024 bits. The default lifetime for self-signed<br />

certificates created on the <strong>Sidewinder</strong> <strong>G2</strong> is five years.<br />

1. In the Certificate Name field, type a name for this certificate.<br />

2. In the Distinguished Name field, create a distinguished name. See<br />

“Understanding Distinguished Name syntax” on page 13-28 for<br />

information on the format that should be used.<br />

Note: The order <strong>of</strong> the specified distinguished name fields must match the order<br />

listed in the certificate.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!