beautypg.com

10 trusted cas – ZyXEL Communications 5 Series User Manual

Page 376

background image

ZyWALL 5/35/70 Series User’s Guide

376

Chapter 19 Certificates

After you click Apply in the My Certificate Create screen, you see a screen that tells you the
ZyWALL is generating the self-signed certificate or certification request.

After the ZyWALL successfully enrolls a certificate or generates a certification request or a
self-signed certificate, you see a screen with a Return button that takes you back to the My
Certificates
screen.

If you configured the My Certificate Create screen to have the ZyWALL enroll a certificate
and the certificate enrollment is not successful, you see a screen with a Return button that
takes you back to the My Certificate Create screen. Click Return and check your
information in the My Certificate Create screen. Make sure that the certification authority
information is correct and that your Internet connection is working properly if you want the
ZyWALL to enroll a certificate online.

19.10 Trusted CAs

Click SECURITY > CERTIFICATES > Trusted CAs to open the Trusted CAs screen.
This screen displays a summary list of certificates of the certification authorities that you have
set the ZyWALL to accept as trusted. The ZyWALL accepts any valid certificate signed by a
certification authority on this list as being trustworthy; thus you do not need to import any
certificate that is signed by one of these certification authorities.

Enrollment Protocol

Select the certification authority’s enrollment protocol from the drop-down list
box.

Simple Certificate Enrollment Protocol (SCEP) is a TCP-based enrollment
protocol that was developed by VeriSign and Cisco.

Certificate Management Protocol (CMP) is a TCP-based enrollment protocol
that was developed by the Public Key Infrastructure X.509 working group of
the Internet Engineering Task Force (IETF) and is specified in RFC 2510.

CA Server Address

Enter the IP address (or URL) of the certification authority server.

CA Certificate

Select the certification authority’s certificate from the CA Certificate drop-
down list box.

You must have the certification authority’s certificate already imported in the
Trusted CAs screen. Click Trusted CAs to go to the Trusted CAs screen
where you can view (and manage) the ZyWALL's list of certificates of trusted
certification authorities.

Request
Authentication

When you select Create a certification request and enroll for a certificate
immediately online
, the certification authority may want you to include a
reference number and key to identify you when you send a certification
request. Fill in both the Reference Number and the Key fields if your
certification authority uses CMP enrollment protocol. Just fill in the Key field if
your certification authority uses the SCEP enrollment protocol.

Key

Type the key that the certification authority gave you.

Apply

Click Apply to begin certificate or certification request generation.

Cancel

Click Cancel to quit and return to the My Certificates screen.

Table 109 SECURITY > CERTIFICATES > My Certificates > Create (continued)

LABEL

DESCRIPTION