88
Update configuration on master
With this option you transfer the current configuration to the master node. In addition
to the user and system configuration, private keys and certificates are copied as well.
Keys and certificates on the master node are overwritten. As an exception, if a service
is using a self-signed certificate, it is not transferred. The following components are
affected:
•
SX-GATE CA (the private key is not copied!)
•
SX-GATE VPN server (IPSec and OpenVPN)
•
connection specific keys of OpenVPN client interfaces
•
SX-GATE mail server (SMTP, IMAP and POP3)
•
SX-GATE reverse proxy
The following keys and certificates are excluded as they are either individual for each
node or the use on the master node does not make sense:
•
private key of the SX-GATE CA
•
SSL proxy CA for inspecting SSL connections
•
SX-GATE administration
12.1-D
Administration server certificate
This certificate is needed for encrypted access to the administration GUI and the
webmail client of SX-GATE.
Use the reverse proxy to access the administration from
the Internet. The reverse proxy can limit access to certain
parts of the administration (e.g. webmail) or enforce two-factor
authentication using client certificates.
Import or issue a new certificate
Install a new certificate in here. SX-GATE can issue a self-signed certificate, but it also
offers the required functions to obtain a certificate from a public certification authority
(CA). Finally you can reinstall a certificate backup here.
Choose action
Please select what you want to do
There are different ways to get a new certificate: