205
Key strength
Old systems like e.g. Windows XP before SP3 might only support keys with max. 2048
bit and an SHA1 hash.
Certificate request
Entering this screen, a certificate request will be generated on SX-GATE. You can sign
it now with the CA certificate.
Extended Key Usage: server authentication
It is recommended to enable this option. By default the Windows IPsec client requires
the VPN server certificate to include this "Extended Key Usage" value.
Depending on the client and its configuration, a client may refuse
to connect if the server certificate does not include this attribute.
Signing certificate
Entering this screen, the certificate will be signed. By pressing the "Finish" button, the
new VPN server key will be installed.
Backup key-pair
The key pair can be exported in PKCS#12 format to save a backup. Please note that
this export also contains the private key which must be kept secret.
There's no way to restore a purchased certificate without
backup.
14.1.1-E
Trusted VPN CA
Certificate based authentication usually implies checking if the presented certificate
has been issued by a trusted certification authority (Root-CA). Here you can specify the
CA trusted by SX-GATE's VPN server. You can use the local SX-GATE CA or upload
the public key of a CA.
Although it is basically possible to have more than one trusted CA, on SX-GATE you
can specify only one to keep things simple. If anyhow the certificates of the peers have
been issued by different CAs, you have to make a decision which of them is to be the
trusted CA.
Содержание SX-GATE
Страница 1: ...State 2016 12 13 V7 0 2 0 User Guide ...
Страница 92: ...12 1 Setup 92 There s no way to restore a purchased certificate without backup ...
Страница 126: ...12 3 3 Groups 126 12 3 3 C Usage This table show in which settings the definition is used ...
Страница 476: ...15 3 Apple iPhone 476 ...