InGateway Documentation, Release 0.0.1
· Client Subnet: specifies the static route that the OpenVPN server sends to the client.
· Client ID: specifies the attribute ID of the client, generally the certificate name or user
name of the client.
4.4.5 Certificate Management
The Simple Certificate Enrollment Protocol (SCEP) is a certificate management protocol formulated jointly
by Cisco and Verisign. This protocol combines PKCS#7 and PKCS#10 standards, and supports extensive
clients and certification authorities (CAs).The certification management parameters are described as follows:
• Enable SCEP: enables or disables the Simple Certificate Enrollment Protocol.
• Force to re-enroll: restarts the certificate enrollment service every time without checking the status of
the current certificate.
• Status: displays the current certificate enrollment status on the device, which can be Initiation, En-
rolling, Re-Enrolling, or Complete.
• Protect Key: specifies the key set during certificate enrollment for encryption of the digital certificate.
You can import or export a certificate only after entering the protection key set during certificate
enrollment.
• Protect Key Confirm: Enter the protection key again to confirm the key.
• Strict CA: sets the ID of a trusted CA. The certificate of a device is enrolled and issued by a trusted
CA. Therefore, you must specify the ID of a trusted CA to bind the device to the CA. Then, the device
completes certificate application, acquisition, revocation, and query through this CA.
• Server URL: specifies the URL of the CA server.
You must specify a CA server URL before-
hand, so that the device can apply to this server for a certificate through SCEP, for example,
http://100.17.145.158:8080/certsrv/mscep/mscep.dll.
• Common Name: specifies the general name of the certificate required.
• FQDN: specifies the fully qualified domain name (FQDN) of the certificate. FQDN is the unique
identifier of an entity on a network and is composed of a host name and a domain name. It can be
resolved into an IP address. For example, host name www and domain name whatever.com form an
FQDN www.whatever.com.
• Unit 1: specifies the name of the first organization of the certificate.
• Unit 2: specifies the name of the second organization of the certificate.
• Domain: specifies the qualified domain name of the certificate.
• Serial Number: specifies the serial number of the certificate.
• Challenge: specifies the challenge code of the certificate, which is required for certificate revocation
(optional).
1.2. InGateway902 User Manual
111
Summary of Contents for InGateway501
Page 1: ...InGateway Documentation Release 0 0 1 zhangning Aug 24 2020...
Page 2: ......
Page 4: ...ii...