12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

VPN Certificates<br />

Local Certificates<br />

VPN Certificates<br />

This section explains how to manage X.509 security certificates using the<br />

<strong>FortiGate</strong> web-based manager. Refer to this module to generate certificate<br />

requests, install signed certificates, import CA root certificates and certificate<br />

revocation lists, and back up and restore installed certificates and private keys.<br />

For additional background information, see the <strong>FortiGate</strong> Certificate Management<br />

User <strong>Guide</strong>.<br />

This section describes:<br />

• Local Certificates<br />

• Remote Certificates<br />

• CA Certificates<br />

• CRL<br />

Local Certificates<br />

Certificate requests and installed server certificates are displayed in the Local<br />

Certificates list. After you submit the request to a CA, the CA will verify the<br />

information and register the contact information on a digital certificate that<br />

contains a serial number, an expiration date, and the public key of the CA. The CA<br />

will then sign and send the signed certificate to you to install on the <strong>FortiGate</strong> unit.<br />

To view certificate requests and/or import signed server certificates, go to VPN ><br />

Certificates > Local Certificates. To view certificate details, select the View<br />

Certificate Detail icon in the row that corresponds to the certificate.<br />

The first entry in the list is the <strong>FortiGate</strong> unit’s self-signed certificate, which you<br />

cannot delete.<br />

Figure 239:Local Certificates list<br />

Download<br />

View Certificate Detail<br />

Delete<br />

Generate<br />

Import<br />

Name<br />

Subject<br />

Generate a local certificate request. See “Generating a certificate<br />

request” on page 370.<br />

Import a signed local certificate. See “Importing a signed server<br />

certificate” on page 373.<br />

The names of existing local certificates and pending certificate<br />

requests.<br />

The Distinguished Names (DNs) of local signed certificates.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 369

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!