Manual

Table Of Contents
D-Link DSR-Series User Manual 101
Section 7 - VPN
Self Certicate Requests
To request a self certicate to be signed by a CA, you can generate a Certicate Signing Request from the router
by entering identication parameters and passing it along to the CA for signing. Once signed, the CAs Trusted
Certicate and signed certicate from the CA are uploaded to activate the self -certicate validating the identity
of this gateway. The self certicate is then used in IPsec and SSL connections with peers to validate the gateways
authenticity.
To generate a certicate signing request:
1. Click VPN > IPSec VPN > Certicates > Self Certicate Requests.
2. Click New Self Certicate.
3. Complete the elds in the table below and click Save.
Field Description
Name Enter a name (identier) for the certicate.
Subject
This eld will populate the CN (Common Name) entry of the generated certicate. Subject names are usually
dened in the following format: CN=<device name>, OU=<department>, O=<organization>, L=<city>,
ST=<state>, C=<country>. For example: CN=router1, OU=my_company, O=mydept, L=SFO, C=US.
Hash Algorithm Select the algorithm from the drop-down menu. Select either MD5 or SHA-1.
Signature Key Length Select the signature key length from the drop-down menu. Select either 512, 1024, or 2048
Application Type Select the application type from the drop-down menu. Select either HTTPS or IPSec.
IP Address Enter an IP address (optional).
Domain Name Enter a domain name (optional).
Email Address Enter your email address.
Save Click Save to save and activate your settings.