3.3 NETWORK Setup Pages
3.3.4.2 Using HTTPS
HTTPS provides secure/encrypted, web-based management and configuration of SecureSync
from a PC. An SSL certificate is required to be in SecureSync in order to make this secure HTTPS
connection.
SecureSync uses OpenSSL library with a simple GUI interface to create certificate requests and
self-signed certificates. Users can then send these certificate requests to an external Certificate
Authority (CA) for the creation of a third party verifiable certificate or use an internal corporate Cer-
tificate Authority. If a Certificate Authority is not available the user can simply use the self-signed
certificate that comes with the unit until it expires or create their own self-signed certificates to
allow the use of HTTPS.
Each SecureSync comes with a default Spectracom self-signed SSL certificate. The typical life
span of a certificate is about 10 years. HTTPS is available using this certificate until this certificate
expires.
The OpenSSL library provides the encryption algorithms used for secure HTTP (HTTPS). The
OpenSSL package also provides tools and software for creating X.509 Certificate Requests, Self
Signed Certificates and Private/Public Keys. For more information on OpenSSL, please see
www.openssl.org
SecureSync's software supports X.509 DER and PEM and P7 PKCS#7 PEM and DER formatted
certificates. The user can create a customer specific X.509 self-signed certificate, an RSA private
key and X.509 certificate request using the web interface. RSA private keys are supported
because they are the most widely accepted (at this time, DSA keys are not supported).
3.3.4.3 Creating an HTTPS Certificate Request
To create an HTTPS Certificate Request:
66
If you exit the HTTPS Setup window while filling out the Certificate Request Para-
meters form before you have hit the Submit button, any information you entered will
not be retained. If you switch between tabs with the HTTPS Setup window, the
information you have entered will be retained until you either leave the HTTPS Setup
window or click the Submit button.
NOTE –
If deleted, the HTTPS certificate cannot be restored. A new certificate will
need to be generated.
NOTE –
If the IP Address or Common Name (Host Name) is changed, you may wish
to regenerate the security certificate. Otherwise you may receive security warnings
from your web browser each time you login.
.
CHAPTER
•
3
SecureSync User Reference Guide Rev. 18
Need help?
Do you have a question about the SecureSync and is the answer not in the manual?