D-Link DWC-1000 User Manual
260
Section 7 - VPN
Self Certificate Requests
To request a self certificate to be signed by a CA, you can generate a Certificate Signing Request from the switch
by entering the identification parameters and passing it along to the CA for signing. Once signed, the CA’s Trusted
Certificate and signed certificate from the CA are uploaded to activate the self-certificate validating the identity
of this switch. The self certificate is then used in IPSec and SSL connections with peers to validate the switch’s
authenticity.
To generate a certificate signing request:
1. Click
VPN
>
IPSec VPN
>
Certificates
>
Self Certificate Requests
.
2. Click
New Self Certificate
.
3. Complete the fields in the table below and click
Save
.
Field
Description
Name
Enter a name (identifier) for the certificate.
Subject
This field will populate the CN (Common Name) entry of the generated certificate. Subject names are
usually defined in the following format: CN=<device name>, OU=<department>, O=<organization>,
L=<city>, ST=<state>, C=<country>. For example: CN=router1, OU=my_company, O=mydept, L=SFO,
C=US.
Hash Algorithm
Select the algorithm from the drop-down menu. Select either
MD5
or
SHA-1
.
Signature Key Length
Select the signature key length from the drop-down menu. Select either
512
,
1024
, or
2048
Application Type
Select the application type from the drop-down menu. Select either
HTTPS
or
IPSec
.
IP Address
Enter an IP address (optional).
Domain Name
Enter a domain name (optional).
Email Address
Enter your email address.
Save
Click
Save
to save and activate your settings.