423
If both, the pure reverse proxy feature and the loadbalancer option of the reverse proxy
are to be used, you might want to consider issuing a wildcard certificate. If e.g. the
hostname "internal.example.com" is used to access the reverse proxy backend and
"www.example.com" addresses the loadbalancer server pool, the certificate can be
issued to "*.example.com".
Subject alternativ names
Most clients also consider this optional certificate property while verifying that the server
certificate belongs to the expected server. Enter all required names and IPs used to
address the server. You can also issue a wildcard certificate (e.g. *.example.com).
Key strength
Old systems like e.g. Windows XP before SP3 might only support keys with max. 2048
bit and an SHA1 hash.
Create a certificate request
On this screen you have to enter the certificate subject.
CN
Issue the certificate to the address which is normally used to connect with the service
from the Internet. Usually this is the Internet DNS name of SX-GATE. You can also
issue a wildcard certificate (e.g. *.example.com), however wildcard certificates are
usually much more expensive.
If both, the pure reverse proxy feature and the loadbalancer option of the reverse proxy
are to be used, you might want to consider issuing a wildcard certificate. If e.g. the
hostname "internal.example.com" is used to access the reverse proxy backend and
"www.example.com" addresses the loadbalancer server pool, the certificate can be
issued to "*.example.com".
Subject alternativ names
Most clients also consider this optional certificate property while verifying that the server
certificate belongs to the expected server. Enter all required names and IPs used to
address the server. You can also issue a wildcard certificate (e.g. *.example.com).
Some CAs ignore this extension. Often the charge for
multidomain and wildcard certificates is considerably higher.
Please clarify this with the CA before you submit the certificate
request.
Key strength
Old systems like e.g. Windows XP before SP3 might only support keys with max. 2048
bit and an SHA1 hash.