Choosing The Appropriate Certificate Installation Method For Your Network - D-Link DWS-1008 - AirPremier MobileLAN Switch Product Manual

8 port 10/100 wireless switch with power over ethernet
Hide thumbs Also See for DWS-1008 - AirPremier MobileLAN Switch:
Table of Contents

Advertisement

Choosing the Appropriate Certificate Installation
Depending on your network environment, you can use any of the following methods to install certificates
and their public-private key pairs. The methods differ in terms of simplicity and security. The simplest
method is also the least secure, while the most secure method is slightly more complex to use.
• Self-signed certificate—The easiest method to use because a CA server is not required.
The switch generates and signs the certificate itself. This method is the simplest but is also
the least secure, because the certificate is not validated (signed) by a CA.
• PKCS #12 object file certificate—More secure than using self-signed certificates, but
slightly less secure than using a Certificate Signing Request (CSR), because the private
key is distributed in a file from the CA instead of generated by the switch itself. The PKCS
#12 object file is more complex to deal with than self-signed certificates. However, you
can use Web View or the CLI to distribute this certificate. The other two methods can be
performed only using the CLI.
• Certificate Signing Request (CSR)—The most secure method, because the switch's public
and private keys are created on the switch itself, while the certificate comes from a trusted
source (CA). This method requires generating the key pair, creating a CSR and sending
it to the CA, cutting and pasting the certificate signed by the CA into the CLI, and then
cutting and pasting the CA's own certificate into the CLI.
The table below lists the steps required for each method and refers you to appropriate instructions.
Certificate Installation Method
Self-signed certificate
PKCS #12 object file certificate
Certificate Signing Request
(CSR) certificate
D-Link DWS-1008 User Manual
Method for Your Network
Steps Required
1. Generate a public-private key pair on
the switch.
2. Generate a self-signed certificate on
the switch.
1. Copy a PKCS #12 object file (public-
private key pair, server certificate, and
CA certificate) from a CA onto the
switch.
2. Enter the one-time password to
unlock the file.
3. Unpack the file into the switch's
certificate and key store.
1. Generate a public-private key pair on
the switch.
2. Generate a CSR on the switch as a
PKCS #10 object file.
3. Give the CSR to a CA and receive a
signed certificate (a PEM-encoded
PKCS #7 object file).
4. Paste the PEM-encoded file into the
CLI to store the certificate on the
switch.
5. Obtain and install the CA's own
certificate.
Instructions
• "Creating Public-Private Key Pairs"
• "Generating Self-Signed Certificates"
"Installing a Key Pair and Certificate
from a PKCS #12 Object File"
• "Creating Public-Private Key Pairs"
• "Creating a CSR and Installing a
Certificate from a PKCS #7 Object
File"
• "Installing a CA's Own Certificate"
1

Advertisement

Table of Contents
loading

Table of Contents