131
12.4.2
Certificates
In this area you can issue certificates which will be signed with the root certificate of
SX-GATE's built-in certification authority (CA). Instead of buying certificates issued by
a commercial CA, using the SX-GATE CA is sufficient for certificates used by closed
user groups.
In the first place, the SX-GATE CA is used to issue certificates for VPN. The VPN server
of SX-GATE requires a certificate of its own, too. Select the predefined entry "VPN" to
issue the certificate for SX-GATE's VPN server.
A table gives you an overview of all available objects. If there are more than 10 entries,
a navigation bar will appear below the right bottom hand corner of the table where you
can page through the entries or open the table in fullscreen mode. Pick an entry by
clicking either its title or the pencil icon to enter the detail view. Add new objects by
clicking "New Entry" below the table on the left. Use the dustbin icon to delete entries.
Name of certificate
Here you have to specify a name for the certificate. It is only used to identify the
certificate, so you can choose any appropriate name.
Export public key
You can download the public key of the certificate here. The file format is PEM.
The private key is not stored on SX-GATE.
Revoked on
Shows date and time when the certificate was marked for inclusion in the certificate
revocation list (CRL) of SX-GATE's CA.
The certificate is not invalidated just by the fact that some point
in time was entered here. First you have to generate a new CRL
using the corresponding CA function and then the new CRL has
to be installed in all relevant applications.
Revoke certificate
When authenticating with certificates an application often verifies the trust chain only. If
a certificate has been signed by a trusted certification authority (CA), the authentication
will succeed if the certificate is not expired. It can however be necessary to invalidate
Содержание SX-GATE
Страница 1: ...State 2016 12 13 V7 0 2 0 User Guide ...
Страница 92: ...12 1 Setup 92 There s no way to restore a purchased certificate without backup ...
Страница 126: ...12 3 3 Groups 126 12 3 3 C Usage This table show in which settings the definition is used ...
Страница 476: ...15 3 Apple iPhone 476 ...