Using Microsoft Ca To Create A Certificate; Sending The Certificate Request; Issuing The Certificate - Watchguard Firebox X20E User Manual

Firmware version 8.6 all firebox x edge e-series standard and wireless models
Hide thumbs Also See for Firebox X20E:
Table of Contents

Advertisement

When you are prompted for the x509 Common Name attribute information, type your fully-
4
qualified domain name (FQDN). Use other information as appropriate.
Follow the instructions from your certificate authority to send the CSR.
5
To create a temporary, self-signed certificate until the CA returns your signed certificate, type a the
command line:
openssl x509 -req -days 30 -in request.csr -key privkey.pem -out sscert.cert
This command creates a certificate inside your current directory that expires in 30 days.
You cannot use a self-signed certificate for VPN remote gateway authentication. We recommend that you
use certificates signed by a trusted third-party Certificate Authority.

Using Microsoft CA to Create a Certificate

Certification Authority is distributed with Windows Server 2003 as a component. If the Certification
Authority is not installed in the Administrative Tools folder of the Control Panel, follow the manufac-
turer's instructions for installation.
When you use this procedure, you act as the certificate authority (CA) and digitally sign your own
request. For the final certificate to be useful, we recommend that you acquire other certificates that
connect your private CA to a widely trusted, third-party certificate authority. You can import these
additional certificates on the Firebox X Edge Certificates page.

Sending the certificate request

Open your web browser. In the location or address bar, type the IP address of the server where
1
the Certification Authority is installed, followed by certsrv.
Example: http://10.0.2.80/certsrv
Click the Request a Certificate link.
2
Click the advanced certificate request link.
3
To submit a CSR you created using OpenSSL, click the Submit a certificate link.
4
Paste the contents of your CSR file into the Saved Request text box.
5
The CSR must be in Base-64 PKCS10 or PKCS7 format.
Close your web browser.
6

Issuing the certificate

Connect to the server where the Certification Authority is installed, if necessary.
1
From the Start Menu, select Control Panel > Administrative Tools > Certification Authority.
2
From the Certification Authority (Local) tree in the left navigation pane, select Your Domain
3
Name > Pending Requests.
Select the CSR in the right navigation pane.
4
From the Action menu, select All Tasks > Issue.
5
Close the Certification Authority window.
6
User Guide
Using Microsoft CA to Create a Certificate
151

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents