09.07.2015 Views

Firebox SSL VPN Gateway Administration Guide - WatchGuard ...

Firebox SSL VPN Gateway Administration Guide - WatchGuard ...

Firebox SSL VPN Gateway Administration Guide - WatchGuard ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Administering the <strong>Firebox</strong> <strong>SSL</strong>To generate a CSR using the Cygwin UNIXenvironment:1 Double-click the Cygwin icon on the desktop.A command window opens with a UNIX bash environment.2 To change to a particular drive, use the command: cddriveLetter:3 At the $ prompt, type the following to generate a CSR:openssl req -new -nodes -keyout privateKeyFilename-out certRequestFilenameFor example:openssl req -new -nodes -keyout private.key -outpublic.csrStatus messages about the private key generation appear. Youwill be prompted for information such as country name.4 When prompted for the Common name, enter the DNSname of the <strong>Firebox</strong> <strong>SSL</strong>.The name that you enter will appear in the certificate and mustmatch the name expected by PCs that connect to the <strong>Firebox</strong> <strong>SSL</strong>.Thus, if you alias DNS names, you will need to use the alias nameinstead.5 Submit your CSR (public.csr) to an authorized certificateprovider such as Verisign. When asked for the type of serverthat the certificate will be used with, indicate “Apache”. (Ifyou indicate “Microsoft”, the certificate might be in PKCS7format and you will need to follow the procedure in“Converting to a PEM-Formatted Certificate” on page 35 toconvert the certificate to a PEM format.)The certificate provider will return a Signed Certificate to you by e-mail within several days.Unencrypting the Private KeyThe following procedure is not needed if you use the CygwinUNIX environment to generate the CSR and private key. Followthis procedure only if the method you use to generate the privatekey results in an encrypted key.34 <strong>Firebox</strong> <strong>SSL</strong> <strong>VPN</strong> <strong>Gateway</strong> <strong>Administration</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!