NB3711 User Manual 4.0
Parameter
Certificate Configuration
Common Name (CN)
The certificate owner’s common name, mainly used to iden-
tify a host
The certificate owner’s email address
Expiry period
The number of days a certificate will be valid from now on
Key size
The length of the private key in bits
DH primes
The number of bits for custom Diffie-Hellman primes
Signature
The signature algorithm when signing certificates
Passphrase
The passphrase for accessing/opening a private key
Please be aware of the fact, that the local random number generator (RNG) provides
pretty good randomness for most applications. If stronger cryptography is mandatory,
we suggest to create the keys at an external RNG device or manage all certificates com-
pletely on a remote certification server. Nevertheless, using a local certificate authority
can issue and manage all required certificates and also run a certificate revokation list
(CRL).
When importing keys, the certificate and key file can be uploaded individually encoded
in PEM/DER or PKCS7 format. All files (CA certificate, certificate and private key)
can also be uploaded in one stroke by using the container format PKCS12. RSA/DSS
keys can be converted from OpenSSH or Dropbear formats. It is possible to specify the
passphrase for opening the private key. Please note that the system will generally apply
the system-wide certificate passphrase on a key when installing the certificate. Thus,
changing the general passphrase will result in all local keys getting equipped with the
new one.
SCEP Configuration
If certificates are getting enrolled by using the Simple Certificate Enrollment Protocol
(SCEP) the following settings can be configured:
Parameter
SCEP Configuration
SCEP status
Specifies whether SCEP is enabled or not
URL
The
SCEP
URL,
usually
in
the
form
http://<host>/<path>/pkiclient.exe
CA fingerprint
The fingerprint of the certificate used to identify the remote
authority. If left empty, any CA will be trusted.
171
Summary of Contents for NB3711
Page 90: ...NB3711 User Manual 4 0 Figure 5 27 Inbound NAPT 90...
Page 92: ...NB3711 User Manual 4 0 Figure 5 29 OpenVPN Configuration 92...
Page 96: ...NB3711 User Manual 4 0 Figure 5 30 OpenVPN Client Management 96...
Page 98: ...NB3711 User Manual 4 0 Figure 5 31 IPsec Administration 98...
Page 104: ...NB3711 User Manual 4 0 Figure 5 34 PPTP Tunnel Configuration 104...
Page 114: ...NB3711 User Manual 4 0 Figure 5 37 SDK Administration 114...
Page 117: ...NB3711 User Manual 4 0 Figure 5 38 SDK Jobs 117...
Page 121: ...NB3711 User Manual 4 0 Figure 5 39 DHCP Server 121...
Page 131: ...NB3711 User Manual 4 0 Figure 5 44 SMS Configuration 131...
Page 158: ...NB3711 User Manual 4 0 Figure 5 55 Remote Authentication 158...
Page 162: ...NB3711 User Manual 4 0 Figure 5 57 Automatic File Configuration 162...
Page 166: ...NB3711 User Manual 4 0 Figure 5 59 Log Viewer 166...
Page 167: ...NB3711 User Manual 4 0 Figure 5 60 Tech Support File 167...
Page 175: ...NB3711 User Manual 4 0 5 9 LOGOUT Please use this menu to log out from the Web Manager 175...
Page 213: ...NB3711 User Manual 4 0 Event Description Table A 3 SDK Examples 213...
Page 214: ......