
Chapter 8: Certificates and Client
Authentication
This chapter describes common tasks involving certificates and client authentication. The chapter also
provides detailed step-by-step instructions for generating certificate signing requests, adding certificates
to the Avaya VPN Gateway (AVG), generating and revoking client certificates, as well as configuring the
VPN Gateway to require client certificates.
The VPN Gateway supports importing certificates in the PEM, NET, DER, PKSCS7, and PKCS12 formats.
The certificates must conform to the X.509 standard. You can create a new certificate, or use an existing
certificate. The VPN Gateway supports using up to 1500 certificates. The basic steps to create a new
certificate using the command line interface of the VPN Gateway are:
• Generate a Certificate Signing Request (CSR) and send it to a Certificate Authority (CA, such as
Entrust or VeriSign) for certification.
• Add the signed certificate to the VPN Gateway.
Note:
Even though the VPN Gateway supports keys and certificates created by using Apache-SSL, OpenSSL,
or Stronghold SSL, the preferred method from a security point of view is to create keys and generate
certificate signing requests from within the VPN Gateway by using the command line interface. This
way, the encrypted private key never leaves the VPN Gateway, and is invisible to the user.
Generating and Submitting a CSR Using the CLI
1. Initiate requesting a certificate signing request (CSR), and provide the necessary
information.
User Guide
April 2013 87
Summary of Contents for 3050-VM
Page 1: ...User Guide Avaya VPN Gateway Release 9 0 NN46120 104 Issue 04 04 April 2013 ...
Page 4: ...4 User Guide April 2013 Comments infodev avaya com ...
Page 12: ...12 User Guide April 2013 ...
Page 20: ...New in this release 20 User Guide April 2013 Comments infodev avaya com ...
Page 30: ...Introducing the VPN Gateway 30 User Guide April 2013 Comments infodev avaya com ...
Page 36: ...Introducing the ASA 310 FIPS 36 User Guide April 2013 Comments infodev avaya com ...
Page 74: ...Upgrading the AVG Software 74 User Guide April 2013 Comments infodev avaya com ...
Page 86: ...Managing Users and Groups 86 User Guide April 2013 Comments infodev avaya com ...
Page 130: ...The Command Line Interface 130 User Guide April 2013 Comments infodev avaya com ...
Page 162: ...Supported Ciphers 162 User Guide April 2013 Comments infodev avaya com ...
Page 212: ...Syslog Messages 212 User Guide April 2013 Comments infodev avaya com ...
Page 242: ...Definition of Key Codes 242 User Guide April 2013 Comments infodev avaya com ...
Page 259: ...Creating a Port Forwarder Authenticator User Guide April 2013 259 ...
Page 266: ...Using the Port Forwarder API 266 User Guide April 2013 Comments infodev avaya com ...
Page 274: ...X 509 274 User Guide April 2013 Comments infodev avaya com ...