The certificates and keys themselves cannot be changed, but a few external attributes can
be changed, depending on the type of the selected entry.
The menu consists of the following fields:
Fields in the menu
Field
Description
Description
Name of the certificate, key, or request.
Certificate is CA Certific-
ate
Mark the certificate as a certificate from a trustworthy certifica-
tion authority (CA).
Certificates issued by this CA are accepted during authentica-
tion (unless specified otherwise under "Phase 1 Profiles").
The function is activated with
.
The function is not activated by default.
Certificate Revocation
List (CRL) Checking
Only for Certificate is a CA certificate =
.
Define the extent to which certificate revocation lists (CRLs) are
to be included in the validation of certificates issued by the own-
er of this certificate.
Possible settings:
•
9*
: No checking of CRLs.
•
-*
: CRLs are always checked.
•
@- 4; 9*"" #" * /*"
(default value): A check is only carried out if a CRL Distribu-
tion Point entry is included in the certificate. This can be de-
termined under "View Details" in the certificate content.
•
5* 0""* */ )" )"
: The set-
tings of the higher level certificate are used, if one exists. It is
does not, the same procedure is used as that described under
"Only if a CRL Distribution Point is present".
Force Certificate to be
trusted
Define that this certificate is to be accepted as the user certific-
ate without further checks during authentication.
The function is activated with
.
The function is not activated by default.
12 VPN
Funkwerk Enterprise Communications GmbH
270
funkwerk TR200aw/bw