
Configuration
Operating Manual PCOM sec br2
1004534-EN-04
| 30
Import certificate into the VPN client
To build up a secure connection between the VPN client and the SecurityBridge, the CA
certificate from the SecurityBridge must be saved in the VPN client.
Procedure
1. To download the certificate directly from the SecurityBridge, enter a passphrase for the
CA certificated in the SecurityBridge under "VPN->Settings"
2. Under "System->Certificates->Certificate download", download a CA certificate with
format PEM on the PC.
3. Start the VPN client and click
Add…
The
Add OpenVPN connection
window opens.
4. Under
Connection name
, enter a name for the connection and in the
SecurityBridge
IP address
field enter the IP address of the SecurityBridge.
5. Select the certificate.
The following options are available:
}
Select certificate from a local directory
You saved the certificate to your configuration PC. Click
Browse file
… and select the
certificate (*.pem).
}
Certificate download
The VPN client can automatically download the certificate. The download is secured by a
passphrase. Further information on the password policy can be found in the Online Help
on the SecurityBridge.
Generate certificates
You can generate new certificates with SecurityBridge. You can generate a server certific-
ate if you want to renew the server certificate without having to redistribute the CA certific-
ates to all the Clients. However, you cannot generate the server certificate if you have pre-
viously uploaded your own CA certificate to the SecurityBridge.
Certificate upload
If you want to use your own certificates, you can store the CA certificate and server certific-
ate with its private key on the SecurityBridge. As they are uploaded the certificates are
checked to ensure they the syntax is correct.
The CA certificate should be stored on the SecurityBridge in order to ensure that the Secur-
ityBridge contains the appropriate CA certificate for the server certificate. The VPN client
cannot download the correct CA certificate until the appropriate CA certificate has been up-
loaded.
Possible formats:
}
PEM
}
Effects:
When a CA certificate is uploaded, any existing private key will be deleted.