09.07.2015 Views

Firebox SSL VPN Gateway Administration Guide - WatchGuard ...

Firebox SSL VPN Gateway Administration Guide - WatchGuard ...

Firebox SSL VPN Gateway Administration Guide - WatchGuard ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Administering the <strong>Firebox</strong> <strong>SSL</strong>The <strong>Firebox</strong> <strong>SSL</strong> accepts a Privacy Enhanced Mail (PEM) formatcertificate file. PEM is a text format that is the Base-64 encodingof the Distinguished Encoding Rules (DER) binary format.The PEM format specifies the use of text BEGIN and END linesthat indicate the type of content that is being encoded.Before you can upload a certificate to the <strong>Firebox</strong> <strong>SSL</strong>, you willneed to generate a Certificate Signing Request (CSR) and privatekey. We recommend using Linux Open<strong>SSL</strong> to administer anycertificate tasks. If Linux is not available, we recommend theCygwin UNIX environment for Windows, which includes anOpen<strong>SSL</strong> module. Instructions for downloading, installing, andusing the Cygwin UNIX environment to generate a CSR areincluded in this section.If you are familiar with certificate manipulation, you can useother tools to create a PEM-formatted file. The certificate thatyou upload to the <strong>Firebox</strong> <strong>SSL</strong> must have the following characteristics:• It must be in PEM format and must include a private key.• The signed certificate and private key must be unencrypted.The following topics describe how to perform the tasks associatedwith generating a CSR:• “About Digital Certificates and <strong>Firebox</strong> <strong>SSL</strong> Operation” onpage 31• “Overview of the Certificate Signing Request” on page 32• “Installing the Cygwin UNIX Environment for Windows” onpage 33• “Generating a CSR” on page 33• “Unencrypting the Private Key” on page 34• “Converting to a PEM-Formatted Certificate” on page 35• “Combining the Private Key with the Signed Certificate” onpage 36• “Generating Trusted Certificates for Multiple Levels” onpage 37• “Uploading a Certificate to the <strong>Firebox</strong> <strong>SSL</strong>” on page 3830 <strong>Firebox</strong> <strong>SSL</strong> <strong>VPN</strong> <strong>Gateway</strong> <strong>Administration</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!