12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Local Certificates<br />

VPN Certificates<br />

Locality (City)<br />

State/Province<br />

Country<br />

e-mail<br />

Key Type<br />

Key Size<br />

Enrollment Method<br />

File Based<br />

Online SCEP<br />

Type the name of the city or town where the <strong>FortiGate</strong><br />

unit is installed.<br />

Type the name of the state or province where the<br />

<strong>FortiGate</strong> unit is installed.<br />

Select the country where the <strong>FortiGate</strong> unit is installed.<br />

Type the contact email address.<br />

Only RSA is supported.<br />

Select 1024 Bit, 1536 Bit or 2048 Bit. Larger keys are<br />

slower to generate but they provide better security.<br />

Select File Based to generate the certificate request.<br />

Select Online SCEP to obtain a signed SCEP-based<br />

certificate automatically over the network.<br />

CA Server URL: Enter the URL of the SCEP server from<br />

which to retrieve the CA certificate.<br />

Challenge Password: Enter the CA server challenge<br />

password.<br />

Downloading and submitting a certificate request<br />

You have to fill out a certificate request and generate the request before you can<br />

submit the results to a CA. For more information, see “Generating a certificate<br />

request” on page 370.<br />

To download and submit a certificate request<br />

1 Go to VPN > Certificates > Local Certificates.<br />

2 In the Local Certificates list, select the Download icon in the row that corresponds<br />

to the generated certificate request.<br />

3 In the File Download dialog box, select Save to Disk.<br />

4 Name the file and save it to the local file system.<br />

5 Submit the request to your CA as follows:<br />

• Using the web browser on the management <strong>com</strong>puter, browse to the CA web<br />

site.<br />

• Follow the CA instructions to place a base-64 encoded PKCS#12 certificate<br />

request and upload your certificate request.<br />

• Follow the CA instructions to download their root certificate and Certificate<br />

Revocation List (CRL), and then install the root certificate and CRL on each<br />

remote client (refer to the browser documentation).<br />

6 When you receive the signed certificate from the CA, install the certificate on the<br />

<strong>FortiGate</strong> unit. See “Importing a signed server certificate” on page 373.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

372 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!