
348
V7122 GatewayUser Guide
Figure 111
Example of a Base64-Encoded X.509 Certificate
-----BEGIN CERTIFICATE-----
MIIDkzCCAnugAwIBAgIEAgAAADANBgkqhkiG9w0BAQQFADA/MQswCQYDVQQGEwJG
UjETMBEGA1UEChMKQ2VydGlwb3N0ZTEbMBkGA1UEAxMSQ2VydGlwb3N0ZSBTZXJ2
ZXVyMB4XDTk4MDYyNDA4MDAwMFoXDTE4MDYyNDA4MDAwMFowPzELMAkGA1UEBhMC
RlIxEzARBgNVBAoTCkNlcnRpcG9zdGUxGzAZBgNVBAMTEkNlcnRpcG9zdGUgU2Vy
dmV1cjCCASEwDQYJKoZIhvcNAQEBBQADggEOADCCAQkCggEAPqd4MziR4spWldGR
x8bQrhZkYhb7+4Q67ecf1janH7GcN/SXsfx7jJpreWULf7v7Cvpr4R7qI
JcmdHIntmf7JPM5n6cDBv17uSW63er7NkVnMFHwK1QaGFLMybFkzaeGrvFm4k3lR
efFhJgHYezYHf44LvPRPAq3o8pWDguJuZDIULPwv
Rw==
-----END CERTIFICATE-----
6
Before continuing, set the parameter HTTPSOnly = 0 to ensure you have a method of
accessing the device in case the new certificate doesn’t work. Restore the previous
setting after testing the configuration.
7
In the
Certificate
screen (
Figure 110
) locate the server certificate loading section.
8
Click
Browse
, navigate to the
cert.txt
file, and then click
Send File
.
9
When the operation is completed, save the configuration (see
Saving Configuration
) and
restart the gateway; the Embedded Web Server uses the provided certificate.
•
The certificate replacement process can be repeated when necessary (for
example, the new certificate expires).
•
It is possible to use the IP address of the gateway (for example, 10.3.3.1)
instead of a qualified DNS name in the Subject Name. This practice is not
recommended since the IP address is subject to changes and may not
uniquely identify the device.
•
The server certificate can also be loaded using ini file using the parameter
‘HTTPSCertFileName’.
Client Certificates
By default, Web servers using SSL provide one-way authentication. The client is certain that
the information provided by the Web server is authentic. When an organizational PKI is used,
two-way authentication may be desired: both client and server should be authenticated using
X.509 certificates. This is achieved by installing a client certificate on the managing PC, and
loading the same certificate (in base64-encoded X.509 format) to the gateway Trusted Root
Certificate Store. The Trusted Root Certificate file should contain both the certificate of the
authorized user and the certificate of the CA.
Since X.509 certificates have an expiration date and time, the gateway must be configured to
use NTP (See
Simple Network Time Protocol Support
) to obtain the current date and time.
Without a correct date and time, client certificates cannot work.
Содержание VCX V7122
Страница 28: ...28 V7122 GatewayUser Guide ...
Страница 39: ...V7122 Gateway User Guide 39 Reader s Notes ...
Страница 40: ...40 V7122 GatewayUser Guide ...
Страница 58: ...58 V7122 GatewayUser Guide Reader s Notes ...
Страница 66: ...66 V7122 GatewayUser Guide Reader s Notes ...
Страница 144: ...144 V7122 GatewayUser Guide Reader s Notes ...
Страница 239: ...V7122 Gateway User Guide 239 Reader s Notes ...
Страница 240: ...240 V7122 GatewayUser Guide ...
Страница 246: ...246 V7122 GatewayUser Guide Reader s Notes ...
Страница 270: ...270 V7122 GatewayUser Guide Reader s Notes ...
Страница 287: ...V7122 Gateway User Guide 287 Reader s Notes ...
Страница 288: ...288 V7122 GatewayUser Guide ...
Страница 294: ...294 V7122 GatewayUser Guide Reader s Notes ...
Страница 300: ...300 V7122 GatewayUser Guide Figure 88 Gateway s Startup Process ...
Страница 315: ...V7122 Gateway User Guide 315 Reader s Notes ...
Страница 316: ...316 V7122 GatewayUser Guide ...
Страница 332: ...332 V7122 GatewayUser Guide Reader s Notes ...
Страница 358: ...358 V7122 GatewayUser Guide Reader s Notes ...
Страница 362: ...362 V7122 GatewayUser Guide Reader s Notes ...
Страница 389: ...V7122 Gateway User Guide 389 Reader s Notes ...
Страница 390: ...390 V7122 GatewayUser Guide ...
Страница 398: ...398 V7122 GatewayUser Guide Reader s Notes ...
Страница 406: ...406 V7122 GatewayUser Guide Reader s Notes ...
Страница 408: ...408 V7122 GatewayUser Guide Reader s Notes ...
Страница 409: ...V7122 Gateway User Guide 409 ...
Страница 419: ...V7122 Gateway User Guide 419 Reader s Notes ...
Страница 437: ...V7122 Gateway User Guide 437 Reader s Notes ...
Страница 452: ...452 V7122 GatewayUser Guide Figure 137 UDP2File Utility ...
Страница 453: ...V7122 Gateway User Guide 453 Reader s Notes ...
Страница 459: ...V7122 Gateway User Guide 459 Reader s Notes ...
Страница 475: ...V7122 Gateway User Guide 475 ...