Digi TransPort WR31 User Manual page 843

Hide thumbs Also See for TransPort WR31:
Table of Contents

Advertisement

Device administration
CA certificate
The filename of the CA certificate.
CA encryption certificate
Sometimes when you get a CA certificate, a CA encryption certificate is installed on the router at
the same time. You can identify a CA encryption certificate by looking at the X.509 Key Usage
section in the certificate. It should display something like the following:
X509v3 Key Usage: critical
Key Encipherment, Data Encipherment
If a CA encryption certificate has been installed by the CA you wish to use for the certificate
request, enter the CA encryption certificate. If no CA encryption certificate has been installed for
the CA, leave this file blank.
CA signature certificate
Sometimes when you get a CA certificate, a CA signature certificate is installed on the router at
the same time. You can identify a CA signature certificate by looking at the X.509 Key Usage
section in the certificate. It should say something like the following
X509v3 Key Usage: critical
Digital Signature, Non Repudiation
If a CA signature certificate has been installed by the CA you wish to use for the certificate
request, enter the CA signature certificate. If no CA signature certificate has been installed for
the CA, leave this file blank.
RSA Private key
Selects either using an existing private key or generating a private key for each certificate
request.
Private key filename
The filename of the private key file to use.
Enrollment Password
Before you can create a certificate request you must first obtain a challenge password from the
Certificate Authority Server. This password is generally obtained from the SCEP CA server by way
of a WEB server or a phone call to the CA Server Administrator. For the Microsoft
you browse to a web interface. If the server requires a challenge password, it will be displayed on
the page along with the CA certificate fingerprint. This challenge password is usually only valid
once and for a short period of time, in this case 60 minutes, meaning a certificate request must
be created after retrieving the challenge password.
Common Name (CN)
A name for the router. This parameter is important, as the router will use the common name as
the router's ID for IKE negotiations.
Digi TransPort WR Routers User Guide
Manage X.509 certificates and host key pairs
®
SCEP server,
832

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents