Appendix A: Uploading Ssl Security Certificates - Black Box EME160A User Manual

Hide thumbs Also See for EME160A:
Table of Contents

Advertisement

APPENDIX A: UPLOADING SSL SECURITY CERTIFICATES

A.1 UPLOADING SSL SECURITY CERTIFICATES
A.1.1 BROWSER CONNECTIONS AND LOG IN ISSUES
NOTE:
The only supported browsers are Google Chrome and Mozilla Firefox. With other browsers, the Web UI might not
load correctly. Newer versions of third-party browsers (from 2020 on), including Chrome, will eventually include
new security restrictions for HTTPS that will affect your connections to our gateways and to our management
web interface.
You have two options to avoid the browser connection issues when connecting to our units' web interfaces. The first
option is to simply use HTTP and not HTTPS. The second option is to replace or upload your own valid, trusted HTTPS
certificate, and, if necessary, add this certificate to your trusted certificate lists within the browser.
A.1.2 HTTPS
The HTTPS port on the units and APS is always enabled. You can change its listening port, if necessary. On the Plus
Gateways, the HTTPS supports TLS v1.1 and v1.2.
The HTTPS cypher suites are not customizable.
To eliminate browser warnings about the self-signed SSL certificate, you will need to replace it.
Use the Upload Certificate File option to upload an SSL certificate that will be used by the unit or APS Web UI for
HTTPS connection (see below).
A.1.3 SSL CERTIFICATE
SSL certificates are generated for DNS host names and not IP addresses. Therefore, you should set a host name for
the Plus gateway in your local DNS server or DHCP server, and then generate the SSL certificate for that host name.
APS on Windows will use the computer's hostname, and L-DCIM can customize the host name in the Settings menu.
Example full hostname: spplus.mycompany.org
Wildcard SSL certificates, such as *.mycompany.org, should also work, but this hasn't been tested.
If the name doesn't match the one in the certificate, the browser will display a security warning.
You can purchase a certificate from a trusted, verified Certificate Authority, such as GoDaddy, or use your company's
own CA if you have one.
NOTE: Only non-password protected certificate files are supported.
1.877.877.2269
BLACKBOX.COM
NEED HELP?
LEAVE THE TECH TO US
LIVE 24/7
TECHNICAL
SUPPORT
1.877.877.2269
43

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Eme161a-r2Eme164aEme168a

Table of Contents