Figure 51: Certificate Server
Table 16: Server Certificate
○ Click on
button after completing all the fields for the server certificate.
○ Click on
to export the server certificate file in “.crt” format.
○ Click on
to export the server key file in “.key” format.
○ Click on
to delete the server certificate if no longer needed.
Cert. Name
Enter the common name for the server certificate.
Note:
It could be any name to identify this certificate.
Example: “ServerCertificate”.
CA Certificate
Select the CA certificate previously generated from the drop-down list.
Example: “CATest”.
Certificate Type
Choose the certificate type from the drop-down list. It can be either a client or a server certificate.
Choose “Server” to generate a server certificate.
Key Length
Choose the key length for generating the CA certificate.
The following values are available:
●
512:
512-bit keys are not secure and it's better to avoid this option.
●
1024
: 1024-bit keys are no longer sufficient to protect against attacks.
●
2048:
2048-bit keys are a good minimum. (Recommended).
●
4096:
4096-bit keys are accepted by nearly all RSA systems. Using 4096-bit keys will dramatically increase
generation time, TLS handshake delays, and CPU usage for TLS operations.
Digest Algorithm
Choose the digest algorithm:
●
SHA1:
This digest algorithm provides a 160-bit fingerprint output based on arbitrary-length input.
●
SHA256:
This digest algorithm generates an almost unique, fixed-size 256 bit hash.
Note:
Hash is a one-way function, it cannot be decrypted back.
Expiration (D)
Enter the validity date for the CA certificate in days.
In our example, set to “120”.
Country / Region
Select a country code from the dropdown list.
Example: “MA”.
State / Province
Enter a state name or province.
Example: “Casablanca”.
City
Enter a city name.
Example: “Casablanca”.
Organization
Enter the organization’s name.
Example: “GS”.
Organizational Unit
This field is the name of the department or organization unit making the request.
Example: “GS Sales”.
Enter an email address.
Example: “[email protected]”