Field
Description
Certificates issued by this CA are accepted during authentica-
tion (unless specified otherwise under "Phase-1 Profiles").
The function is activated with
True
.
The function is disabled by default.
Certificate Revocation
List (CRL) Checking
Only for Certificate is a CA certificate =
True
.
Define the extent to which certificate revocation lists (CRLs) are
to be included in the validation of certificates issued by the own-
er of this certificate.
Possible settings:
•
Disabled
: No checking of CRLs.
•
Always
: CRLs are always checked.
•
Only if a CRL Distribution Point is present
(default value): A check is only carried out if a CRL Distribu-
tion Point entry is included in the certificate. This can be de-
termined under "View Details" in the certificate content.
•
Use Settings from superior certificate
: The set-
tings of the higher level certificate are used, if one exists. It is
does not, the same procedure is used as that described under
"Only if a CRL Distribution Point is present".
Force Certificate to be
trusted
Define that this certificate is to be accepted as the user certific-
ate without further checks during authentication.
The function is activated with
True
.
The function is disabled by default.
Caution
It is extremely important for VPN security that the integrity of all certificates manually
marked as trustworthy (certification authority and user certificates) is ensured. The dis-
played "fingerprints" can be used to check this integrity: Compare the displayed values
with the fingerprints specified by the issuer of the certificate (e.g. on the Internet). It is
sufficient to check one of the two values.
Funkwerk Enterprise Communications GmbH
11 VPN
bintec R1xxx/R3xxx/R4xxx
361