NetModule NB3700 User Manual page 155

Hide thumbs Also See for NB3700:
Table of Contents

Advertisement

Parameter
Common Name (CN)
E-Mail
Expiry period
Key size
Passphrase
Please be aware of the fact, that the local random number generator (RNG) provides
pretty good randomness for most applications. If stronger cryptography is mandatory,
we suggest to create the keys at an external RNG device or manage all certificates com-
pletely on a remote certification server. Nevertheless, using a local certificate authority
can issue and manage all required certificates and also run a certificate revokation list
(CRL).
When importing keys, the certificate and key file can be uploaded individually encoded
in PEM/DER or PKCS7 format. All files (CA certificate, certificate and private key)
can also be uploaded in one stroke by using the container format PKCS12. RSA/DSS
keys can be converted from OpenSSH or Dropbear formats. It is possible to specify the
passphrase for opening the private key. Please note that the system will generally apply
the system-wide certificate passphrase on a key when installing the certificate. Thus,
changing the general passphrase will result in all local keys getting equipped with the
new one.
SCEP Configuration
If certificates are getting enrolled by using the Simple Certificate Enrollment Protocol
(SCEP) the following settings can be configured:
Parameter
SCEP status
URL
CA fingerprint
Fingerprint algorithm
Poll interval
NB3700 User Manual 3.8
Certificate Configuration
The certificate owner's common name, mainly used to iden-
tify a host
The certificate owner's email address
The number of days a certificate will be valid from now on
The length of the private key in bit
The passphrase for accessing/opening a private key
SCEP Configuration
Specifies whether SCEP is enabled or not
The
SCEP
URL,
http://<host>/<path>/pkiclient.exe
The fingerprint of the certificate used to identify the remote
authority. If left empty, any CA will be trusted.
The fingerprint algorithm for identifying the CA (MD5 or
SHA1)
The polling interval in seconds for a certificate request
155
usually
in
the
form

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents