
12 Administration
12-20
VPN 3002 Hardware Client User Guide
Administration | Certificate Management | Enrollment |
Request Generated
The Manager displays this screen when the system has successfully generated a certificate request. The
request is a Base-64 encoded file in PKCS-10 format (Public Key Certificate Syntax-10), which most
CAs recognize or require. The system automatically saves this file in flash memory with the filename
shown in the screen (
pkcsNNNN.txt).
In generating the request, the system also generates the private key used in the PKI process. That key
remains on the VPN 3002, and it is not visible.
You must complete the enrollment and certificate installation process within two weeks of generating
the request.
Figure 12-22: Administration | Certificate Management | Enrollment | Request Generated screen
To go to the Certificate Installation screen, click the highlighted Certificate Installation page link.
Enrolling with a Certificate Authority
To send the certificate request to a CA, enroll, and receive your digital certificates, follow these steps.
(These are cut-and-paste steps; your CA may follow different procedures. In any case, you must end up
with certificates saved as text files on your PC or other reachable network host.)
1 Select and copy the certificate request from the browser window to your clipboard.
2 Use a browser to connect to the CA’s Web site. Navigate to the screen that lets you submit a PKCS-10
request via cut-and-paste.
3 Paste the certificate request in the CA screen, and submit the request.
4 The CA should respond with a new browser screen that says the certificates were successfully
generated. That screen also should include active links that let you “Download the root certificate”
and “Download the identity certificate.”
5 With the secondary mouse button, click the root certificate download link and select
Save Link As or
Save Target As. You want to save the file as a text file on your PC or other reachable network host; do
not open it or install it in the browser. The browser opens a dialog box that lets you navigate to the
desired location and enter a filename. Use a name that clearly identifies this as a root certificate, with
a
.txt extension.
Komentarze do niniejszej Instrukcji