132
a certificate ahead of time, e.g. when an employee leaves the company or a notebook
with such a certificate has been stolen.
To create a complete CRL, certificates must not be deleted
before the original expiration date has been reached.
Undo revocation
A revoked certificate can be re-activated. Remember to generate and distribute a new
CRL after unlocking the certificate.
Issue new certificate
With this function you can issue or renew the certificate. The new certificate will be
signed by the SX-GATE CA and is valid for one year.
You should renew a certificate only right before it expires.
Otherwise it will not be possible to include the old certificate in
the certificate revocation list.
Issue certificate
On this screen you have to enter the certificate subject.
CN
If this certificate is to be used by a server program, you should enter the DNS name
or the Internet IP address of the system. You can also issue a wildcard certificate
(e.g. *.example.com). For a user certificate you might want to enter the name or email
address.
Subject alternativ names
The certificate subject is a composition of all the data you entered before. You can add
an optional alternative name to the subject. For a server certificate you should enter
additional hostnames and IP addresses of the server. You can also issue wildcard
certificates (e.g. *.example.org). For a user certificate you should enter the email
address.
Enter password
A private key which has to remain secret will also be part of the new certificate. To
guarantee the privacy of the certificate while it is forwarded to the intended user, the
PKCS#12 file is protected with a password. Forward PKCS#12 file and password
separately. The password should be transmitted using a secure channel.