Field
Description
The function is enabled with
)
.
The function is disabled by default.
Certificate Revocation
List (CRL) Checking
Only for Certificate is CA Certificate =
)
Define the extent to which certificate revocation lists (CRLs)
are to be included in the validation of certificates issued by the
owner of this certificate.
Possible settings:
•
!"
: No CRLs check.
•
8!
: CRLs are always checked.
•
>G ! 6 !
1!
(default value): A check is only carried out if a CRL
Distribution Point entry is included in the certificate. This can
be determined under "View Details" in the certificate content.
•
=! !! !1
: The set-
tings of the higher level certificate are used, if one exists. It is
does not, the same procedure is used as that described un-
der "Only if a CRL Distribution Point is present".
Force certificate to be
trusted
Define that this certificate is to be accepted as the user certific-
ate without further checks during authentication.
The function is enabled with
)
.
The function is disabled by default.
Caution
It is extremely important for VPN security that the integrity of all certificates
manually marked as trustworthy (certification authority and user certificates)
is ensured. The displayed "fingerprints" can be used to check this integrity:
Compare the displayed values with the fingerprints specified by the issuer of
the certificate (e.g. on the Internet). It is sufficient to check one of the two
values.
Gigaset Communications GmbH
2 System Management
hybird 120 Gigaset Edition
43