Version 3R2
Security Appliance User Guide
12-1
PKI
AND
X.509/D
IGITAL
C
ERTIFICATES
12
This chapter describes the Public Key Infrastructure (PKI) and
X.509/Digital Certificates feature. It includes the following topics:
•
About Public Key Infrastructure and X.509/Digital Certificates
•
PKI Basics
•
CLI Commands
A B O U T P U B L I C K E Y I N F R A S T R U C T U R E A N D
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
X . 5 0 9 / D I G I T A L C E R T I F I C A T E S
PKI is designed to be used with IPSec instead of PSK and Manual Key.
Although complex to set-up, it provides a higher level of security.
Different ways to use PKI include:
Use of self-signed certificate
Use a Certificate Authority
Certificate revocation lists
Chain validation