Chapter 9 Certificates
P-660R-F1 Series User’s Guide
137
9.6 Certificates Technical Reference
This section provides technical background information about the topics covered in this chapter.
9.6.1 Certificates Overview
The ZyXEL Device can use certificates (also called digital IDs) to authenticate users. Certificates are
based on public-private key pairs. A certificate contains the certificate owner’s identity and public
key. Certificates provide a way to exchange public keys for use in authentication.
The ZyXEL Device uses certificates based on public-key cryptology to authenticate users attempting
to establish a connection, not to encrypt the data that you send after establishing a connection. The
method used to secure the data that you send through an established connection depends on the
type of connection. For example, a VPN tunnel might use the triple DES encryption algorithm.
The certification authority uses its private key to sign certificates. Anyone can then use the
certification authority’s public key to verify the certificates.
A certification path is the hierarchy of certification authority certificates that validate a certificate.
The ZyXEL Device does not trust a certificate if any certificate on its path has expired or been
revoked.
Certification authorities maintain directory servers with databases of valid and revoked certificates.
A directory of certificates that have been revoked before the scheduled expiration is called a CRL
(Certificate Revocation List). The ZyXEL Device can check a peer’s certificate against a directory
server’s list of revoked certificates. The framework of servers, software, procedures and policies
that handles keys is called PKI (Public-Key Infrastructure).
Server Port
This field displays the default server port number of the protocol that you select
in the
Access Protocol
field.
You may change the server port number if needed, however you must use the
same server port number that the directory server uses.
389 is the default server port number for LDAP.
Login Setting
Login
The ZyXEL Device may need to authenticate itself in order to assess the
directory server. Type the login name (up to 31 ASCII characters) from the
entity maintaining the directory server (usually a certification authority).
Password
Type the password (up to 31 ASCII characters) from the entity maintaining the
directory server (usually a certification authority).
Back
Click this to return to the
Directory Servers
screen.
Apply
Click this to save your changes.
Cancel
Click this to restore your previously saved settings.
1.
At the time of writing, LDAP is the only choice of directory server access protocol.
LABEL
DESCRIPTION
Summary of Contents for P-660R-F1 series
Page 2: ......
Page 8: ...Certifications P 660R F1 Series User s Guide 8 ...
Page 16: ...P 660R F1 Series User s Guide 16 ...
Page 18: ...P 660R F1 Series User s Guide 18 ...
Page 62: ...Chapter 4 WAN Setup P 660R F1 Series User s Guide 62 ...
Page 104: ...Chapter 7 Firewalls P 660R F1 Series User s Guide 104 ...
Page 140: ...Chapter 9 Certificates P 660R F1 Series User s Guide 140 ...
Page 144: ...Chapter 10 Static Route P 660R F1 Series User s Guide 144 ...
Page 162: ...Chapter 12 Dynamic DNS Setup P 660R F1 Series User s Guide 162 ...
Page 190: ...Chapter 15 System P 660R F1 Series User s Guide 190 ...
Page 204: ...Chapter 16 Logs P 660R F1 Series User s Guide 204 ...
Page 212: ...Chapter 18 Diagnostic P 660R F1 Series User s Guide 212 ...
Page 216: ...Chapter 19 Troubleshooting P 660R F1 Series User s Guide 216 ...
Page 220: ...P 660R F1 Series User s Guide 220 ...
Page 222: ...P 660R F1 Series User s Guide 222 ...
Page 246: ...P 660R F1 Series User s Guide 246 ...
Page 250: ...P 660R F1 Series User s Guide 250 ...
Page 258: ...P 660R F1 Series User s Guide 258 3 Click OK to close the window Figure 172 Java Sun ...
Page 266: ...P 660R F1 Series User s Guide 266 ...
Page 267: ...P 660R F1 Series User s Guide 267 ...
Page 268: ...P 660R F1 Series User s Guide 268 ...