EKI-6333AC-4GP User Manual
74
certificates for them. In a web of trust scheme, the signer is either the key's owner (a
self-signed certificate) or other users (“endorsements”) whom the person examining
the certificate might know and trust. The device also plays as a CA role.
Certificates are an important component of Transport Layer Security (TLS,
sometimes called by its older name SSL), where they prevent an attacker from
impersonating a secure website or other server. They are also used in other
important applications, such as email encryption and code signing. Here, it can be
used in IPSec tunneling for user authentication.
3.4.4.1
Configuration
To access this page, click
Object Definition
>
Certificate
>
Configuration
.
The
Configuration
screen allows user to create Root Certificate Authority (CA)
certificate and configure to set enable of SCEP. Root CA is the top-most certificate of
the tree, the private key of which is used to “sign” other certificates.
Figure 3.89 Object Definition > Certificate > Configuration
When
Generate
button is applied, the
Root CA Certificate Configuration
screen
appears. The required information to be filled for the root CA includes the name, key,
subject name and validity.
Figure 3.90 Object Definition > Certificate > Configuration > Root CA Certificate
Configuration
The following table describes the items in the previous figure.
Item
Description
Name
Enter a Root CA certificate name. It will be a certificate file name.
Key
This field is to specify the key attribute of certificate.
Key Type
to set public-key cryptosystems. It only supports
RSA now.
Key Length
to set s the size measured in bits of the key
used in a cryptographic algorithm.
Digest Algorithm
to set identifier in the signature algorithm
identifier of certificates.
Subject Name
This field is to specify the information of certificate.
Country(C)
is the two-letter ISO code for the country where
your organization is located.
State(ST)
is the state where your organization is located.
Location(L)
is the location where your organization is
located.
Organization(O)
is the name of your organization.
Organization Unit(OU)
is the name of your organization
unit.
Common Name(CN)
is the name of your organization.
is the email of your organization. It has to be email
address style.
Validity Period
This field is to specify the validity period of certificate.