
Note:
When using an ASA 310-FIPS running in FIPS mode, the private key associated with a
certificate cannot be imported. All private keys must be generated on the HSM card itself
due to the FIPS security requirements.
There are two ways to install a key and certificate into the VPN Gateway :
• Copy-and-paste the key/certificate.
• Download the key/certificate from a TFTP/FTP/SCP/SFTP server.
The VPN Gateway supports importing certificates and keys in these formats:
• PEM
• NET
• DER
• PKCS7 (certificate only)
• PKCS8 (keys only, used in WebLogic)
• PKCS12 (also known as PFX)
Besides these formats, keys in the proprietary format used in MS IIS 4 can be imported by the
VPN Gateway, as wells as keys from Netscape Enterprise Server or iPlanet Server. Importing
keys from Netscape Enterprise Server or iPlanet Server however, require that you first use a
conversion tool. For more information about the conversion tool, contact Avaya. See
Customer
service
on page 16 for contact information.
When it comes to exporting certificates and keys from the VPN Gateway, you can specify to
save in the PEM, NET, DER, or PKCS12 format when using the
export
command. If you
choose to use the
display
command (which requires a copy-and-paste operation), you are
restricted to saving certificates and keys in the PEM format only.
Note:
When performing a copy-and-paste operation to add a certificate or key, you must always
use the PEM format.
Copy-and-Paste Certificates
The following steps demonstrate how to add a certificate using the copy-and-paste method.
Note:
If you connect to one of the VPN Gateways in the cluster by using a console connection,note
that HyperTerminal under Microsoft Windows may be slow to complete copy-and-paste
operations. If your security policy permits enabling Telnet or SSH access to the VPN
Gateway, use a Telnet or SSH client and connect to the Management IP address instead.
Adding Certificates to the AVG
User Guide
April 2013 93
Содержание 3050-VM
Страница 1: ...User Guide Avaya VPN Gateway Release 9 0 NN46120 104 Issue 04 04 April 2013 ...
Страница 4: ...4 User Guide April 2013 Comments infodev avaya com ...
Страница 12: ...12 User Guide April 2013 ...
Страница 20: ...New in this release 20 User Guide April 2013 Comments infodev avaya com ...
Страница 30: ...Introducing the VPN Gateway 30 User Guide April 2013 Comments infodev avaya com ...
Страница 36: ...Introducing the ASA 310 FIPS 36 User Guide April 2013 Comments infodev avaya com ...
Страница 74: ...Upgrading the AVG Software 74 User Guide April 2013 Comments infodev avaya com ...
Страница 86: ...Managing Users and Groups 86 User Guide April 2013 Comments infodev avaya com ...
Страница 130: ...The Command Line Interface 130 User Guide April 2013 Comments infodev avaya com ...
Страница 162: ...Supported Ciphers 162 User Guide April 2013 Comments infodev avaya com ...
Страница 212: ...Syslog Messages 212 User Guide April 2013 Comments infodev avaya com ...
Страница 242: ...Definition of Key Codes 242 User Guide April 2013 Comments infodev avaya com ...
Страница 259: ...Creating a Port Forwarder Authenticator User Guide April 2013 259 ...
Страница 265: ...This will print current statistics every 3 seconds Monitoring the Port Forwarder User Guide April 2013 265 ...
Страница 266: ...Using the Port Forwarder API 266 User Guide April 2013 Comments infodev avaya com ...
Страница 274: ...X 509 274 User Guide April 2013 Comments infodev avaya com ...