![Comtrol DeviceMaster PRO Installation And Configuration Manual Download Page 83](http://html.mh-extra.com/html/comtrol/devicemaster-pro/devicemaster-pro_installation-and-configuration-manual_2648823083.webp)
DeviceMaster Installation and Configuration Guide
: 2000594 Rev. F
DeviceMaster Security - 83
Key and Certificate Management
Key and Certificate Management
Key and Certificate management is only available in
Network | Keys/Cert
web page.
Key and Certificate Management Option Descriptions
RSA Key pair used by
SSL and SSH servers
This is a private/public key pair that is used for two purposes:
It is used by some cipher suites to encrypt the SSL/TLS handshaking messages.
Possession of the private portion of this key pair allows an eavesdropper to both
decrypt traffic on SSL/TLS connections that use RSA encryption during
handshaking.
It is used to sign the Server RSA Certificate in order to verify that the
DeviceMaster is authorized to use the server RSA identity certificate.
Possession of the private portion of this key pair allows somebody to pose as the
DeviceMaster.
If the Server RSA Key is to be replaced, a corresponding RSA identity
certificate must also be generated and uploaded or clients are not able to verify
the identity certificate.
RSA Server Certificate
used by SSL servers
This is the RSA identity certificate that the DeviceMaster uses during SSL/TLS
handshaking to identify itself. It is used most frequently by SSL server code in
the DeviceMaster when clients open connections to the DeviceMaster's secure
web server or other secure TCP ports. If a DeviceMaster serial port
configuration is set up to open (as a client) a TCP connection to another server
device, the DeviceMaster also uses this certificate to identify itself as an SSL
client if requested by the server.
In order to function properly, this certificate must be signed using the Server
RSA Key. This means that the server RSA certificate and server RSA key must
be replaced as a pair.