![ZyXEL Communications P-2612HW-F1 - Скачать руководство пользователя страница 292](http://html1.mh-extra.com/html/zyxel-communications/p-2612hw-f1/p-2612hw-f1_user-manual_944584292.webp)
Chapter 15 Certificates
P-2612HW Series User’s Guide
292
Public and Private Keys
When using public-key cryptology for authentication, each host has two keys. One
key is public and can be made openly available; the other key is private and must
be kept secure. Public-key encryption in general works as follows.
1
Tim wants to send a private message to Jenny. Tim generates a public-private key
pair. What is encrypted with one key can only be decrypted using the other.
2
Tim keeps the private key and makes the public key openly available.
3
Tim uses his private key to encrypt the message and sends it to Jenny.
4
Jenny receives the message and uses Tim’s public key to decrypt it.
5
Additionally, Jenny uses her own private key to encrypt a message and Tim uses
Jenny’s public key to decrypt the message.
The ZyXEL Device uses certificates based on public-key cryptology to authenticate
users attempting to establish a connection. The method used to secure the data
that you send through an established connection depends on the type of
connection. For example, a VPN tunnel might use the triple DES encryption
algorithm.
The certification authority uses its private key to sign certificates. Anyone can then
use the certification authority’s public key to verify the certificates.
Certification Path
A certification path is the hierarchy of certification authority certificates that
validate a certificate. The ZyXEL Device does not trust a certificate if any
certificate on its path has expired or been revoked.
Certificate Directory Servers
Certification authorities maintain directory servers with databases of valid and
revoked certificates. A directory of certificates that have been revoked before the
scheduled expiration is called a CRL (Certificate Revocation List). The ZyXEL
Device can check a peer’s certificate against a directory server’s list of revoked
certificates. The framework of servers, software, procedures and policies that
handles keys is called PKI (public-key infrastructure).
Advantages of Certificates
Certificates offer the following benefits.
Содержание P-2612HW-F1 -
Страница 2: ......
Страница 8: ...Safety Warnings P 2612HW Series User s Guide 8...
Страница 10: ...Contents Overview P 2612HW Series User s Guide 10...
Страница 22: ...Table of Contents P 2612HW Series User s Guide 22...
Страница 24: ...24...
Страница 56: ...Chapter 3 Wizards P 2612HW Series User s Guide 56...
Страница 88: ...88...
Страница 120: ...Chapter 6 WAN Setup P 2612HW Series User s Guide 120...
Страница 136: ...Chapter 7 LAN Setup P 2612HW Series User s Guide 136...
Страница 168: ...Chapter 8 Wireless LAN P 2612HW Series User s Guide 168...
Страница 184: ...Chapter 9 Network Address Translation NAT P 2612HW Series User s Guide 184...
Страница 250: ...Chapter 12 Firewall P 2612HW Series User s Guide 250...
Страница 290: ...Chapter 14 VPN P 2612HW Series User s Guide 290...
Страница 320: ...Chapter 15 Certificates P 2612HW Series User s Guide 320...
Страница 324: ...Chapter 16 Static Route P 2612HW Series User s Guide 324...
Страница 356: ...Chapter 19 Dynamic DNS Setup P 2612HW Series User s Guide 356...
Страница 382: ...Chapter 21 Universal Plug and Play UPnP P 2612HW Series User s Guide 382...
Страница 384: ...384...
Страница 406: ...Chapter 23 Logs P 2612HW Series User s Guide 406...
Страница 458: ...458...
Страница 494: ...Appendix B Pop up Windows JavaScripts and Java Permissions P 2612HW Series User s Guide 494...
Страница 530: ...Appendix D Wireless LANs P 2612HW Series User s Guide 530...
Страница 547: ...Index P 2612HW Series User s Guide 547...