340
V6100 and V7122 User Guide
Figure 119
Example of a Base64-Encoded X.509 Certificate
-----BEGIN CERTIFICATE-----
MIIDkzCCAnugAwIBAgIEAgAAADANBgkqhkiG9w0BAQQFADA/MQswCQYDVQQGEwJG
UjETMBEGA1UEChMKQ2VydGlwb3N0ZTEbMBkGA1UEAxMSQ2VydGlwb3N0ZSBTZXJ2
ZXVyMB4XDTk4MDYyNDA4MDAwMFoXDTE4MDYyNDA4MDAwMFowPzELMAkGA1UEBhMC
RlIxEzARBgNVBAoTCkNlcnRpcG9zdGUxGzAZBgNVBAMTEkNlcnRpcG9zdGUgU2Vy
dmV1cjCCASEwDQYJKoZIhvcNAQEBBQADggEOADCCAQkCggEAPqd4MziR4spWldGR
x8bQrhZkYhb7+4Q67ecf1janH7GcN/SXsfx7jJpreWULf7v7Cvpr4R7qI
JcmdHIntmf7JPM5n6cDBv17uSW63er7NkVnMFHwK1QaGFLMybFkzaeGrvFm4k3lR
efFhJgHYezYHf44LvPRPAq3o8pWDguJuZDIULPwv
Rw==
-----END CERTIFICATE-----
6
Before continuing, set the parameter HTTPSOnly = 0 to ensure you have a method of
accessing the device in case the new certificate doesn’t work. Restore the previous
setting after testing the configuration.
7
In the Certificates screen (
Figure 118
) locate the server certificate loading section.
8
Click
Browse
and navigate to the
cert.txt
file, click
Send File
.
9
When the operation is completed, save the configuration (See
Save Configuration
) and
restart the V7122; the Embedded Web Server uses the provided certificate.
The certificate replacement process can be repeated when necessary (e.g., the
new certificate expires).
It is possible to use the IP address of the V7122 (e.g., 10.3.3.1) instead of a
qualified DNS name in the Subject Name. This practice is not recommended
since the IP address is subject to changes and may not uniquely identify the
device.
The server certificate can also be loaded via
ini
file using the parameter
‘HTTPSCertFileName’.
Client Certificates
By default, Web servers using SSL provide one-way authentication. The client is certain that
the information provided by the Web server is authentic. When an organizational PKI is used,
two-way authentication may be desired: both client and server should be authenticated using
X.509 certificates. This is achieved by installing a client certificate on the managing PC, and
loading the same certificate (in base64-encoded X.509 format) to the V7122 Trusted Root
Certificate Store. The Trusted Root Certificate file should contain both the certificate of the
authorized user and the certificate of the CA.
Since X.509 certificates have an expiration date and time, the V7122 must be configured to
use NTP (See
Simple Network Time Protocol Support
) to obtain the current date and time.
Without a correct date and time, client certificates cannot work.
Содержание TP-1610
Страница 28: ...28 V6100 and V7122 User Guide Reader s Notes ...
Страница 48: ...48 V6100 and V7122 User Guide Reader s Notes ...
Страница 72: ...72 V6100 and V7122 User Guide Reader s Notes ...
Страница 80: ...80 V6100 and V7122 User Guide Reader s Notes ...
Страница 151: ...V6100 and V7122 User Guide 151 Figure 83 Log off Prompt 2 Click OK in the prompt the Web session is logged off ...
Страница 152: ...152 V6100 and V7122 User Guide Reader s Notes ...
Страница 262: ...262 V6100 and V7122 User Guide Reader s Notes ...
Страница 284: ...284 V6100 and V7122 User Guide Reader s Notes ...
Страница 291: ...V6100 and V7122 User Guide 291 Figure 95 V7122 Startup Process ...
Страница 324: ...324 V6100 and V7122 User Guide Reader s Notes ...
Страница 354: ...354 V6100 and V7122 User Guide Reader s Notes ...
Страница 374: ...374 V6100 and V7122 User Guide Reader s Notes ...
Страница 382: ...382 V6100 and V7122 User Guide Figure 130 Example of a User Information File Reader s Notes ...
Страница 392: ...392 V6100 and V7122 User Guide Reader s Notes ...
Страница 409: ...V6100 and V7122 User Guide 409 Reader s Notes ...
Страница 413: ...V6100 and V7122 User Guide 413 Reader s Notes ...
Страница 425: ...V6100 and V7122 User Guide 425 Figure 145 UDP2File Utility Reader s Notes ...
Страница 431: ...V6100 and V7122 User Guide 431 Reader s Notes ...
Страница 447: ...V6100 and V7122 User Guide 447 Reader s Notes ...
Страница 449: ...V6100 and V7122 User Guide 449 Figure 146 Connection Module CM Figure 147 OSN Server Figure 148 Hard Drive Module HDMX ...
Страница 483: ...V6100 and V7122 User Guide 483 Reader s Notes ...