Chapter 15 Certificates
ADSL Series User’s Guide
194
The ZyXEL Device uses certificates based on public-key cryptology to authenticate users attempting
to establish a connection. The method used to secure the data that you send through an
established connection depends on the type of connection. For example, a VPN tunnel might use
the triple DES encryption algorithm.
The certification authority uses its private key to sign certificates. Anyone can then use the
certification authority’s public key to verify the certificates.
Certification Path
A certification path is the hierarchy of certification authority certificates that validate a certificate.
The ZyXEL Device does not trust a certificate if any certificate on its path has expired or been
revoked.
Certificate Directory Servers
Certification authorities maintain directory servers with databases of valid and revoked certificates.
A directory of certificates that have been revoked before the scheduled expiration is called a CRL
(Certificate Revocation List). The ZyXEL Device can check a peer’s certificate against a directory
server’s list of revoked certificates. The framework of servers, software, procedures and policies
that handles keys is called PKI (public-key infrastructure).
Advantages of Certificates
Certificates offer the following benefits.
• The ZyXEL Device only has to store the certificates of the certification authorities that you decide
to trust, no matter how many devices you need to authenticate.
• Key distribution is simple and very secure since you can freely distribute public keys and you
never need to transmit private keys.
Certificate File Formats
The certification authority certificate that you want to import has to be in one of these file formats:
• Binary X.509: This is an ITU-T recommendation that defines the formats for X.509 certificates.
• PEM (Base-64) encoded X.509: This Privacy Enhanced Mail format uses 64 ASCII characters to
convert a binary X.509 certificate into a printable form.
• Binary PKCS#7: This is a standard that defines the general syntax for data (including digital
signatures) that may be encrypted. The ZyXEL Device currently allows the importation of a
PKS#7 file that contains a single certificate.
• PEM (Base-64) encoded PKCS#7: This Privacy Enhanced Mail (PEM) format uses 64 ASCII
characters to convert a binary PKCS#7 certificate into a printable form.
Note: Be careful not to convert a binary file to text during the transfer process. It is easy
for this to occur since many programs use text files by default.
Summary of Contents for P-660HN-F1
Page 2: ...Videos ADSL Series User s Guide 2 Videos File Sharing Video Example 55 QoS Video Example 76...
Page 6: ...Document Conventions ADSL Series User s Guide 6 Server Firewall Router Switch...
Page 8: ...Safety Warnings ADSL Series User s Guide 8...
Page 10: ...Contents Overview ADSL Series User s Guide 10...
Page 19: ...19 PART I User s Guide...
Page 20: ...20...
Page 26: ...Chapter 1 Introduction ADSL Series User s Guide 26...
Page 40: ...Chapter 2 Introducing the Web Configurator ADSL Series User s Guide 40...
Page 80: ...Chapter 3 Tutorials ADSL Series User s Guide 80...
Page 81: ...81 PART II Technical Reference...
Page 82: ...82...
Page 130: ...Chapter 6 Wireless ADSL Series User s Guide 130...
Page 160: ...Chapter 8 Routing ADSL Series User s Guide 160...
Page 164: ...Chapter 9 DNS Route ADSL Series User s Guide 164...
Page 182: ...Chapter 11 Network Address Translation NAT ADSL Series User s Guide 182...
Page 190: ...Chapter 13 Firewall ADSL Series User s Guide 190...
Page 202: ...Chapter 15 Certificates ADSL Series User s Guide 202...
Page 222: ...Chapter 16 VPN ADSL Series User s Guide 222...
Page 226: ...Chapter 17 System Monitor ADSL Series User s Guide 226...
Page 228: ...Chapter 18 User Account ADSL Series User s Guide 228...
Page 242: ...Chapter 24 Backup Restore ADSL Series User s Guide 242...
Page 246: ...Chapter 25 Diagnostic ADSL Series User s Guide 246...
Page 254: ...Chapter 26 Troubleshooting ADSL Series User s Guide 254...
Page 262: ...Chapter 27 Product Specifications ADSL Series User s Guide 262...
Page 302: ...Appendix B Setting Up Your Computer s IP Address ADSL Series User s Guide 302...
Page 310: ...Appendix C Pop up Windows Java Script and Java Permissions ADSL Series User s Guide 310...
Page 334: ...Appendix E Common Services ADSL Series User s Guide 334...
Page 355: ...Appendix F Open Software Announcements ADSL Series User s Guide 355...
Page 356: ...Appendix F Open Software Announcements ADSL Series User s Guide 356...
Page 360: ...Appendix G Legal Information ADSL Series User s Guide 360...