203
If you don't use the VPN server of SX-GATE or if you authenticate VPN connections
by preshared keys only, this area is not effective.
Export public key
If the VPN peer requires the public key of the SX-GATE VPN server certificate, it can
be downloaded here.
Please assure that it is really the public key of the VPN server
which is requested. Perhaps the public key of the root CA which
issued the SX-GATE certificate is required instead.
Issue or import VPN server key-pair
To specify a new certificate for the SX-GATE VPN server, you can import it here from a
PKCS#12 file or issue a new one by the local SX-GATE CA. If an other SX-GATE issued
the certificate you might have received a setup archive. In addition to the PKCS#12 file
it includes the required parameters to setup an IPSec VPN with the other SX-GATE.
Import VPN server key-pair
Select file
Please select the PKCS#12 file or the setup archive containing the PKCS#12 file. The
import password is required to open the PKCS#12 file.
Check VPN server certificate
Please check the contents of the PKCS#12 file and the contents of the currently
installed certificate.
Depending on the authentication mode the installation of the new
certificate might break the currently active VPN connections.
If a VPN connection is accepted if the certificate has been
issued by a trusted certification authority (Root-CA), the issuer
of the old and the new certificate must not be different. However
if the public key of the SX-GATE VPN server is used for
authentication, the new public key has to be installed by the
peers to get a working VPN again.
Check CA certificate
The trusted VPN server CA should usually be the same CA which issued the VPN
server certificate. If the CA certificate is included in the uploaded PKCS#12 file it may
be imported along with the server certificate.