12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

VPN Certificates<br />

CRL<br />

CRL<br />

A Certificate Revocation List (CRL) is a list of CA certificate subscribers paired<br />

with certificate status information. Installed CRLs are displayed in the CRL list.<br />

The <strong>FortiGate</strong> unit uses CRLs to ensure that the certificates belonging to CAs and<br />

remote clients are valid.<br />

To view installed CRLs, go to VPN > Certificates > CRL.<br />

Figure 249:Certificate revocation list<br />

Import Import a CRL. See “Importing a certificate revocation list” on page 377.<br />

Name<br />

The names of existing certificate revocation lists. The <strong>FortiGate</strong> unit<br />

assigns unique names (CRL_1, CRL_2, CRL_3, and so on) to<br />

certificate revocation lists when they are imported.<br />

Subject Information about the certificate revocation lists.<br />

Delete icon Delete the selected CRL from the <strong>FortiGate</strong> configuration.<br />

View Certificate<br />

Detail icon<br />

Download icon<br />

Display CRL details such as the issuer name and CRL update dates.<br />

See example Figure 250.<br />

Save a copy of the CRL to a local <strong>com</strong>puter.<br />

View Certificate Detail<br />

Download<br />

Figure 250:CRL Certificate Detail<br />

Importing a certificate revocation list<br />

Certificate revocation lists from CA web sites must be kept updated on a regular<br />

basis to ensure that clients having revoked certificates cannot establish a<br />

connection with the <strong>FortiGate</strong> unit. After you download a CRL from the CA web<br />

site, save the CRL on a <strong>com</strong>puter that has management access to the <strong>FortiGate</strong><br />

unit.<br />

Note: When the CRL is configured with an LDAP, HTTP, and/or SCEP server, the latest<br />

version of the CRL is retrieved automatically from the server when the <strong>FortiGate</strong> unit does<br />

not have a copy of it or when the current copy expires.<br />

To import a certificate revocation list, go to VPN > Certificates > CRL and select<br />

Import.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 377

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!