Field
Description
field. This file must be provided to the CA and the received
certificate must then be imported manually to your device.
•
5
: The key is requested from a CA using the Simple Cer-
tificate Enrolment Protocol.
Generate Private Key
Only for Mode =
:
Select an algorithm for key creation.
(default value) and
!
are available.
Also select the length of the key to be created.
Possible values:
)
,
2+,
,
,
)+
,
,
,
+
.
Please note that a key with a length of 512 bits could be rated
as unsecure, whereas a key of 4096 bits not only needs a lot of
time to create, but also occupies a major share of the resources
during IPSec processing. A value of 768 or more is, however,
recommended and the default value is 1024 bits.
SCEP URL
Only for Mode =
5
Enter the URL of the SCEP server, e.g. ht-
tp://scep.bintec-elmeg.com:8080/scep/scep.dll
Your CA administrator can provide you with the necessary data.
CA Certificate
Only for Mode =
5
Select the CA certificate.
• In
! >
: In CA Name, enter the name of the CA
certificate of the certification authority (CA) from which you
wish to request your certificate, e.g.
3> >-
. Your CA ad-
ministrator can provide you with the necessary data.
If no CA certificates are available, the device will first down-
load the CA certificate of the relevant CA. It then continues
with the enrolment process, provided no more important para-
meters are missing. In this case, it returns to the Generate
Certificate Request menu.
If the CA certificate does not contain a CRL distribution point
(Certificate Revocation List, CRL), and a certificate server is
bintec elmeg GmbH
11 System Management
elmeg hybird 120 / hybird 130
129