Spectracom Corporation
Model 9289
NetClock/NTP Network Time Provider Instruction Manual
3-77
For more information on OpenSSL please see
www.openssl.org
.
The user can create a customer specific x509 self-signed certificate, an RSA private key and
x509 certificate request using the web browser user interface. RSA private keys are supported
because they are the most widely accepted. At this time DSA keys are not supported.
The user is required to select a signature algorithm, a private key passphrase of at least 4
characters, a private key bit length, the certificates expiration in days and at least one of the
remaining fields. It is recommended that the user consult their Certificate Authority for the
required fields in an x509 certificate request. Spectracom recommends all fields be filled out and
match the information given to your certificate authority. For example, use all abbreviations,
spellings, URLs, and company departments recognized by the Certificate Authority. This helps
in avoiding issues with the Certificate Authority having issues to reconciling certificate request
and company record information.
The Common Name field is the name of the host being authenticated. The Common Name field
in the x509 certificate must match the hostname, IP address, or URL used to reach the host via
HTTPS. This field should be filled with the hostname or IP address of the NetClock. Spectracom
recommends using a static IP address, because DHCP-generated IP addresses can change. If
the hostname or IP address changes, the x509 certificate must be regenerated. If using only
self-signed certificates, the user should choose the fields based on the company’s security
policy.
Note that it can take several minutes for the certificate request, the private key, and self-signed
certificate are created. The larger the key, the longer amount of time is required. It is
recommended that a key bit length be a power of 2 or multiple of 2. The key bit length chosen is
typically 1024, but can range from 512 to 4096. Long key bit lengths of up to 4096 are not
recommended because they can take hours to generate. The most common key bit length is
the value 1024.
The user is provided with several signature algorithm choices. The signature algorithm or
message digest is most commonly MD5. Other secure options include SHA1 and RMD160.
Consult your Web Browser documentation and Certificate Authority for key bit lengths and
signature algorithms supported.
If a system is rebooted during this time, the certificate will not be created. When the operation is
completed, the user will see a certificate request in the certificate request text box. A digital file
copy of the certificate request can be found in the root directory with the file name cert.csr. This
file can be retrieved using FTP, SCP or SFTP. The certificate request can also be cut and paste
from the certificate request text box on the web browser user interface.
3.4.15.5 Requesting Certificate Authority Certificates
Once the processing to create the certificate request, RSA private key and self-signed certificate
is completed the web browser user interface will display the certificate request.
The user can submit this certificate request to the company’s Certificate Authority for a real
verifiable, authenticable third party certificate. Until this certificate is received the user’s self-
signed certificate displaying the information shown above can be used.
Summary of Contents for 9289
Page 18: ...Model 9289 Spectracom Corporation NetClock NTP Network Time Provider Instruction Manual 1 8...
Page 36: ...Model 9289 Spectracom Corporation NetClock NTP Network Time Provider Instruction Manual 2 18...
Page 154: ...Model 9289 Spectracom Corporation NetClock NTP Network Time Provider Instruction Manual 3 118...