Administration Guide
153
APPENDIX C
Installing Windows Certificates
The Firebox SSL VPN Gateway includes the Certificate Request Generator to automatically create a cer-
tificate request. After the file is returned from the Certificate Authority, it can be uploaded to the Firebox
SSL VPN Gateway. When the file is uploaded, it is converted automatically to the correct format for use.
If you do not want to use the Certificate Request Generator to create the signed certificate, use Linux
OpenSSL to administer any certificate tasks. If Linux is not available, Cygwin UNIX environment for Win-
dows is recommended, which includes an OpenSSL module. Instructions for downloading, installing,
and using the Cygwin UNIX environment to generate a CSR are included in this section.
If you are familiar with certificate manipulation, you can use other tools to create a PEM-formatted file.
The certificate that you upload to the Firebox SSL VPN Gateway must have the following characteristics:
• It must be in PEM format and must include a private key
• The signed certificate and private key must be unencrypted
If Linux OpenSSL is not available, install the Cygwin UNIX environment for Windows. When you install
Cygwin, you must choose the OpenSSL modules as described in the following steps.
To install Cygwin
1
Use a Web browser to navigate to http://www.cygwin.com and click
Install Cygwin Now
.
2
Follow the on-screen instructions to open the setup installer.
3
In the
Cygwin Setup
dialog box, click
Next
.
4
Click
Install from Internet
and then click
Next
.
5
Accept the default root installation directory settings and then click
Next
.
6
Accept the default local package directory setting and then click
Next
.
7
In the
Internet Connection
screen, click
Use IE5 Settings
and then click
Next
.
8
In the list of Available Download Sites, click
ftp://ftp.nas.nasa.gov
and then click
Next
.
9
In the
Select Packages
screen, click the
View
button.
10
Scroll the packages list to locate in the Package column
openssl: The OpenSSL runtime
environment
and
openssl-devel: The OpenSSL development environment
.
11
In the
New
column for those two entries, click
Skip
.
The current version number of Cygwin appears.
Содержание Firebox SSL Series
Страница 1: ...WatchGuard Firebox SSL VPN Gateway Administration Guide Firebox SSL VPN Gateway ...
Страница 40: ...Using the Firebox SSL VPN Gateway 30 Firebox SSL VPN Gateway ...
Страница 118: ...Setting the Priority of Groups 108 Firebox SSL VPN Gateway ...
Страница 146: ...Managing Client Connections 136 Firebox SSL VPN Gateway ...
Страница 168: ...Generating Trusted Certificates for Multiple Levels 158 Firebox SSL VPN Gateway ...
Страница 190: ...180 Firebox SSL VPN Gateway ...
Страница 198: ...188 Firebox SSL VPN Gateway ...