Digi Connect WAN Series User Manual page 152

Hide thumbs Also See for Connect WAN Series:
Table of Contents

Advertisement

Digi Connect WAN Family web interface
Virtual Private Network (VPN) identities
Upload VPN identity keys and certificates
Use this section to upload VPN RSA or DSA identity keys and certificates. You can install up to 5 VPN
identity certificates. You can install up to 5 VPN identity keys.
You can use identity certificate and key files in ASN.1 DER or PEM Base64 encoded formats.
Enter or browse to the name of the file to upload in the Upload File field. A password is required in
the Password field only if the host key file is encrypted. Click the Upload button to upload the file.
Installed VPN identity certificates
This table lists any VPN identity certificates that are loaded in the VPN Identities database.
Action: Select to perform allowable actions on the entry. The only allowable action is to delete
n
the entry.
Subject: The entity that received the certificate.
n
Issuer: The entity that issued the certificate.
n
Expiration: The expiration date of the certificate.
n
Delete button: Deletes all certificates selected in the Action column from the database.
n
Installed VPN identity keys
Lists any VPN identity keys that are in the VPN Identities database.
Action: Select to perform allowable actions on the entry. The only allowable action is to delete
n
the entry.
Type: The type of encryption of the VPN identity key: RSA (public key cryptography algorithm)
n
or DSA (digital signature algorithm).
Matching Key: The private key associated with the certificate, if any exists.
n
Delete button: Deletes all the keys selected in the Action column from the database.
n
Key generation / enrollment
Use this section to set parameters for handling SCEP enrollment requests. A SCEP enrollment request
creates a private key and sends a request to the SCEP server to generate a SCEP CA certificate. You
can install up to 4 pending SCEP enrollment requests.
Enrollment request parameters are as follows:
SCEP Enrollment Server URL: The URL for the SCEP server.
n
CA Certificate: The name of the CA certificate to be obtained from the SCEP server.
n
Encryption Certificate
n
Signing Certificate: There are roles in a certificate enrollment request: The CA that signs the
enrollment request, and the CA that encrypts the request. These two options are indices into
the CAs in the Digi device's certificate database, and both sign and encrypt the request. This
information is typically downloaded from the SCEP CA table.
RSA Key Length (bits): The number of characters in the key.
n
Digi Connect WAN Family User Guide
Administration
152

Advertisement

Table of Contents
loading

Table of Contents