Chapter 15 The Certificates Screens
User’s Guide
185
Certification authorities maintain directory servers with databases of valid and
revoked certificates. A directory of certificates that have been revoked before the
scheduled expiration is called a CRL (Certificate Revocation List). The WiMAX
Modem can check a peer’s certificate against a directory server’s list of revoked
certificates. The framework of servers, software, procedures and policies that
handles keys is called PKI (public-key infrastructure).
15.4.1.1 Advantages of Certificates
Certificates offer the following benefits.
• The WiMAX Modem only has to store the certificates of the certification
authorities that you decide to trust, no matter how many devices you need to
authenticate.
• Key distribution is simple and very secure since you can freely distribute public
keys and you never need to transmit private keys.
15.4.1.2 Self-signed Certificates
You can have the WiMAX Modem act as a certification authority and sign its own
certificates.
15.4.1.3 Factory Default Certificate
The WiMAX Modem generates its own unique self-signed certificate when you first
turn it on. This certificate is referred to in the GUI as the factory default
certificate.
15.4.1.4 Certificate File Formats
Any certificate that you want to import has to be in one of these file formats:
• Binary X.509: This is an ITU-T recommendation that defines the formats for
X.509 certificates.
• PEM (Base-64) encoded X.509: This Privacy Enhanced Mail format uses
lowercase letters, uppercase letters and numerals to convert a binary X.509
certificate into a printable form.
• Binary PKCS#7: This is a standard that defines the general syntax for data
(including digital signatures) that may be encrypted. A PKCS #7 file is used to
transfer a public key certificate. The private key is not included. The WiMAX
Modem currently allows the importation of a PKS#7 file that contains a single
certificate.
• PEM (Base-64) encoded PKCS#7: This Privacy Enhanced Mail (PEM) format uses
lowercase letters, uppercase letters and numerals to convert a binary PKCS#7
certificate into a printable form.
Note: Be careful to not convert a binary file to text during the transfer process. It is
easy for this to occur since many programs use text files by default.
Summary of Contents for MAX-306M1
Page 2: ......
Page 8: ...Safety Warnings User s Guide 8...
Page 10: ...Contents Overview User s Guide 10...
Page 24: ...List of Figures User s Guide 24...
Page 30: ...30...
Page 63: ...63 PART II Basic Screens The Main Screen 38 The Setup Screens 65...
Page 64: ...64...
Page 72: ...72...
Page 84: ...Chapter 7 The LAN Configuration Screens User s Guide 84...
Page 96: ...Chapter 8 The WAN Configuration Screens User s Guide 96...
Page 108: ...Chapter 9 The VPN Transport Screens User s Guide 108...
Page 118: ...Chapter 10 The NAT Configuration Screens User s Guide 118...
Page 130: ...130...
Page 148: ...Chapter 12 The Service Configuration Screens User s Guide 148...
Page 158: ...Chapter 13 The Phone Screens User s Guide 158...
Page 164: ...Chapter 14 The Phone Book Screens User s Guide 164...
Page 166: ...166...
Page 188: ...Chapter 15 The Certificates Screens User s Guide 188...
Page 198: ...Chapter 16 The Firewall Screens User s Guide 198...
Page 218: ...Chapter 19 QoS User s Guide 218...
Page 234: ...Chapter 20 The Logs Screens User s Guide 234...
Page 247: ...247 PART VI Troubleshooting and Specifications Troubleshooting 249 Product Specifications 257...
Page 248: ...248...
Page 256: ...Chapter 22 Troubleshooting User s Guide 256...
Page 264: ...Chapter 23 Product Specifications User s Guide 264...
Page 266: ...266...
Page 298: ...Appendix B Setting Up Your Computer s IP Address User s Guide 298...
Page 308: ...Appendix C Pop up Windows JavaScripts and Java Permissions User s Guide 308...
Page 352: ...Appendix E Importing Certificates User s Guide 352...
Page 354: ...Appendix F SIP Passthrough User s Guide 354...
Page 370: ...Appendix I Customer Support User s Guide 370...
Page 376: ...Index User s Guide 376...