Version 6.6
99
MP-11x & MP-124
User's Manual
9. Configuring Certificates
9.4
Self-Signed Certificates
The device is shipped with an operational, self-signed server certificate. The subject name
for this default certificate is 'ACL_nnnnnnn', where
nnnnnnn
denotes the serial number of
the device. However, this subject name may not be appropriate for production and can be
changed while still using self-signed certificates.
To change the subject name and regenerate the self-signed certificate:
1.
Before you begin, ensure the following:
•
You have a unique DNS name for the device (e.g.,
dns_name.corp.customer.com). This name is used to access the device and
should therefore, be listed in the server certificate.
•
No traffic is running on the device. The certificate generation process is disruptive
to traffic and should be executed during maintenance time.
2.
Open the Certificates page (see 'Replacing the Device's Certificate' on page
95
).
3.
In the 'Subject Name [CN]' field, enter the fully-qualified DNS name (FQDN) as the
certificate subject, select the desired private key size (in bits), and then click
Generate
self-signed
; after a few seconds, a message appears displaying the new subject
name.
4.
Save the configuration with a device reset (see 'Saving Configuration' on page
324
)
for the new certificate to take effect.
9.5
TLS Server Certificate Expiry Check
The device can periodically check the validation date of the installed TLS server certificate.
This periodic check interval is user-defined. In addition, within a user-defined number of
days before the installed TLS server certificate expires, the device can be configured to
send the SNMP trap, acCertificateExpiryNotifiaction to notify of the impending certificate
expiration.
To configure TLS certificate expiry checks and notification:
1.
Open the Certificates page (see 'Replacing the Device's Certificate' on page
95
).
2.
In the 'TLS Expiry Check Start' field, enter the number of days before the installed TLS
server certificate is to expire at which the device must send a trap to notify of this.
Figure
9-4: TLS Expiry Settings Group
3.
In the 'TLS Expiry Check Period' field, enter the periodical interval (in days) for
checking the TLS server certificate expiry date. By default, the device checks the
certificate every 7 days.
4.
Click the
Submit TLS Expiry Settings
button.
9.6
Configuring Certificate Revocation Checking (OCSP)
Some Public-Key Infrastructures (PKI) can revoke a certificate after it has been issued.
You can configure the device to check whether a peer's certificate has been revoked, using
the Online Certificate Status Protocol (OCSP). When OCSP is enabled, the device queries
Summary of Contents for Media Pack MP-124
Page 2: ......
Page 14: ...User s Manual 14 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 18: ...User s Manual 18 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 23: ...Part I Getting Started with Initial Connectivity...
Page 24: ......
Page 32: ...User s Manual 32 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 33: ...Part II Management Tools...
Page 34: ......
Page 36: ...User s Manual 36 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 86: ...User s Manual 86 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 88: ...User s Manual 88 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 93: ...Part III General System Settings...
Page 94: ......
Page 103: ...Part IV General VoIP Configuration...
Page 104: ......
Page 130: ...User s Manual 130 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 164: ...User s Manual 164 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 174: ...User s Manual 174 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 199: ...Part V Gateway Application...
Page 200: ......
Page 202: ...User s Manual 202 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 240: ...User s Manual 240 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 286: ...User s Manual 286 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 287: ...Part VI Stand Alone Survivability Application...
Page 288: ......
Page 296: ...User s Manual 296 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 319: ...Part VII Maintenance...
Page 320: ......
Page 326: ...User s Manual 326 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 359: ...Part VIII Status Performance Monitoring and Reporting...
Page 360: ......
Page 389: ...Part IX Diagnostics...
Page 390: ......
Page 404: ...User s Manual 404 Document LTRT 65422 MP 11x MP 124...
Page 417: ...Part X Appendix...
Page 418: ......
Page 580: ...User s Manual 580 Document LTRT 65422 MP 11x MP 124 Reader s Notes...