For a server certificate, the
Common Name
provided must be the DNS-resolvable fully
qualified domain name (FQDN) used by the cluster. When a client receives the
certificate from the server, the client browser will display a warning if the
Common
Name
does not match the hostname of the request URI.
For a client certificate, the
Common Name
in the client’s copy of the certificate is only
compared to the Common Name in the copy of the client certificate on the server, so
Common Name
can be any value.
3. Visit the website of an SSL Certificate Authority (CA) to submit the
cert.csr
file to the CA.
4. Once the CA returns your signed certificate (usually in email), go to
on page 822 for more information.
Generating a CSR and Installing a Certificate on Windows Using IIS
Using Internet Information Services (IIS) is optional when creating and managing certificates for
Equalizer Layer 7 HTTPS clusters and clients. In fact, one of the advantages of using Equalizer is
that only one server certificate is required for an HTTPS cluster. The cluster certificate is installed
on Equalizer, not on the servers in the HTTPS cluster. So, you do not need to use IIS on each
server to create and install certificates. This reduces the amount of effort spent administering
server certificates.
For Layer 4 TCP and UDP clusters, certificates are not installed on Equalizer, and you will need to
install a server certificate on each server in the cluster (since Equalizer is not doing any
HTTPS/SSL processing in Layer 4).
Please refer to the
IIS documentation from Microsoft
.for descriptions for generating a CSR and
installing a signed certificate on Windows using IIS.
Copyright © 2014 Coyote Point Systems, A Subsidiary of Fortinet, Inc.
All Rights Reserved.
821
Equalizer Administration Guide
Summary of Contents for Equalizer GX Series
Page 18: ......
Page 32: ...Overview 32 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 42: ......
Page 52: ......
Page 64: ......
Page 72: ......
Page 76: ......
Page 228: ......
Page 238: ......
Page 476: ......
Page 492: ......
Page 530: ......
Page 614: ......
Page 626: ......
Page 638: ......
Page 678: ......
Page 732: ...Using SNMP Traps 732 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 754: ......
Page 790: ......
Page 804: ......
Page 842: ......
Page 866: ......