NetModule NB3710 User Manual page 186

Hide thumbs Also See for NB3710:
Table of Contents

Advertisement

NB3710
User Manual for NRSW version 4.4
Parameter
Country (C)
Common Name (CN)
E-Mail
Expiry period
Key size
DH primes
Signature
Passphrase
Please be aware of the fact, that the local random number generator (RNG) provides pretty good
randomness for most applications. If stronger cryptography is mandatory, we suggest to create the
keys at an external RNG device or manage all certificates completely on a remote certification server.
Nevertheless, using a local certificate authority can issue and manage all required certificates and also
run a certificate revokation list (CRL).
When importing keys, the certificate and key file can be uploaded individually encoded in PEM/DER
or PKCS7 format. All files (CA certificate, certificate and private key) can also be uploaded in one
stroke by using the container format PKCS12. RSA/DSS keys can be converted from OpenSSH or
Dropbear formats. It is possible to specify the passphrase for opening the private key. Please note
that the system will generally apply the system-wide certificate passphrase on a key when installing
the certificate. Thus, changing the general passphrase will result in all local keys getting equipped with
the new one.
SCEP Configuration
If certificates are getting enrolled by using the Simple Certificate Enrollment Protocol (SCEP) the
following settings can be configured:
Parameter
SCEP status
URL
CA fingerprint
Fingerprint algorithm
Poll interval
Request timeout
ID type
Password
Certificate Configuration
The certificate owner's country (usually a TLD abbreviation)
The certificate owner's common name, mainly used to identify a host
The certificate owner's email address
The number of days a certificate will be valid from now on
The length of the private key in bits
The number of bits for custom Diffie-Hellman primes
The signature algorithm when signing certificates
The passphrase for accessing/opening a private key. This passphrase
is initialized to a random string the first time you log in. (see 5.1.1)
SCEP Configuration
Specifies whether SCEP is enabled or not
The
SCEP
URL,
http://<host>/<path>/pkiclient.exe
The fingerprint of the certificate used to identify the remote authority.
If left empty, any CA will be trusted.
The fingerprint algorithm for identifying the CA (MD5 or SHA1)
The polling interval in seconds for a certificate request
The max. polling time in seconds for a certificate request
Can be IP, Email or DNS
The password for the scep server.
186
usually
in
the
form

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the NB3710 and is the answer not in the manual?

Questions and answers

This manual is also suitable for:

Nb2700

Table of Contents