WCB-200 Admin Guide
Installing a new CA certificate
1. Specify the name of the certificate file or select Browse to choose from a list. CA certificates
must be in X.509 or PKCS #7 format.
2. Select Install to install a new CA certificate.
CA certificate import formats
The import mechanism supports importing the ASN.1 DER encoded X.509 certificate directly or as
part of two other formats:
• PKCS #7 (widely used by Microsoft products)
• PEM, defined by OpenSSL (popular in the Unix world)
• The CRL can be imported as an ASN.1 DER encoded X.509 certificate revocation list directly
or as part of a PEM file.
Content and
file format
ASN.1 DER encoded
X.509 certificate
X.509 certificate in
PKCS #7 file
X.509 certificate in
PEM file
ASN.1 DER encoded
X.509 CRL
X.509 CRL in PEM file One X.509 CRL
Certificate and private key store
This list displays all certificates installed on the WCB-200. The WCB-200 uses these certificates
and private keys to authenticate itself to peers.
The following information is displayed for each certificate in the list:
• Issued to: Name of the certificate holder. Select the name to view the contents of the
certificate.
• Issued by: Name of the CA that issued the certificate.
• Current usage: Lists the services that are currently using this certificate.
• Delete: Select to remove the certificate from the certificate store.
43
Items carried in the file
One X.509 certificate
One X.509 certificate
One or more X.509 certificate
One X.509 CRL
4 Working with the WCB-200
Description
This is the most basic format
supported, the certificate without any
envelope.
Popular format with Microsoft products.
Popular format in the Unix world.
X.509 DER certificate is base64
encoded and placed between
"-----BEGIN CERTIFICATE-----"
and
"-----END CERTIFICATE-----"
lines. Multiple certificates can be
repeated in the same file.
Most basic format supported for CRL.
Same format as X.509 certificate in
PEM format, except that the lines
contain BEGIN CRL and END CRL.
Need help?
Do you have a question about the WCB-200 and is the answer not in the manual?