When a certificate is downloaded automatically, i.e. if CA Certificate =
-2+
is selected, all the certificates needed for the operation are loaded automatically.
If all the necessary certificates are already available in the system, these can also be selec-
ted manually.
Select the Certificate Request button to request or import more certificates.
The menu System Management->Certificates->Certificate List->Certificate Request
consists of the following fields:
Fields in the Certificate Request menu.
Field
Description
Certificate Request De-
scription
Enter a unique description for the certificate.
Mode
Select the way in which you want to request the certificate.
Possible settings:
•
.3+
(default value): Your device generates a PKCS#10
for the key. This file can then be uploaded directly in the
browser or copied in the
menu using the View details
field. This file must be provided to the CA and the received
certificate must then be imported manually to your device.
•
%
: The key is requested from a CA using the Simple Cer-
tificate Enrolment Protocol.
Generate Private Key
Only for Mode =
.3+
Select an algorithm for key creation.
?,
(default value) and
-,
are available.
Also select the length of the key to be created.
Possible values:
,
(
,
,
,
,
.
Please note that a key with a length of 512 bits could be rated
as unsecure, whereas a key of 4096 bits not only needs a lot of
time to create, but also occupies a major share of the resources
during IPSec processing. A value of 768 or more is, however,
recommended and the default value is 1024 bits.
7 System Management
bintec elmeg GmbH
72
be.IP 4isdn