User`s guide
Chapter 11 Certificates Screens
LAN-Cell 2 User’s Guide
268
Create a certification
request and save it
locally for later
manual enrollment
Select Create a certification request and save it locally for later manual
enrollment to have the LAN-Cell generate and store a request for a certificate.
Use the My Certificate Details screen to view the certification request and
copy it to send to the certification authority.
Copy the certification request from the My Certificate Details screen (see
Section 11.2.1 on page 259) and then send it to the certification authority.
Create a certification
request and enroll for
a certificate
immediately online
Select Create a certification request and enroll for a certificate
immediately online to have the LAN-Cell generate a request for a certificate
and apply to a certification authority for a certificate.
You must have the certification authority’s certificate already imported in the
Trusted CAs screen.
When you select this option, you must select the certification authority’s
enrollment protocol and the certification authority’s certificate from the drop-
down list boxes and enter the certification authority’s server address. You also
need to fill in the Reference Number and Key if the certification authority
requires them.
Enrollment Protocol Select the certification authority’s enrollment protocol from the drop-down list
box.
Simple Certificate Enrollment Protocol (SCEP) is a TCP-based enrollment
protocol that was developed by VeriSign and Cisco.
Certificate Management Protocol (CMP) is a TCP-based enrollment protocol
that was developed by the Public Key Infrastructure X.509 working group of
the Internet Engineering Task Force (IETF) and is specified in RFC 2510.
CA Server Address Enter the IP address (or URL) of the certification authority server.
CA Certificate Select the certification authority’s certificate from the CA Certificate drop-
down list box.
You must have the certification authority’s certificate already imported in the
Trusted CAs screen. Click Trusted CAs to go to the Trusted CAs screen
where you can view (and manage) the LAN-Cell's list of certificates of trusted
certification authorities.
Enrollment via an RA If you select Create a certification request and enroll for a certificate
immediately online, you can select this option to apply for a certificate
through a RA (Registration Authority). The RA is an intermediary authorized by
a CA to verify each subscriber's identity and forward the requests to the CA.
After the CA signs and issues the certificates, the RA distributes the
certificates to the subscribers.
RA Signing Certificate If you select Enrollment via an RA, select the CA's RA signing certificate from
the drop-down list box. You must have the certificate already imported in the
Trusted CAs screen.
Click Trusted CAs to go to the Trusted CAs screen where you can view (and
manage) the LAN-Cell's list of certificates of trusted certification authorities.
RA Encryption
Certificate
If you select Enrollment via an RA, select the CA's RA encryption certificate
from the drop-down list box. You must have the certificate already imported in
the Trusted CAs screen.
Click Trusted CAs to go to the Trusted CAs screen where you can view (and
manage) the LAN-Cell's list of certificates of trusted certification authorities.
Request
Authentication
When you select Create a certification request and enroll for a certificate
immediately online, the certification authority may want you to include a
reference number and key to identify you when you send a certification
request. Fill in both the Reference Number and the Key fields if your
certification authority uses CMP enrollment protocol. Just fill in the Key field if
your certification authority uses the SCEP enrollment protocol.
Key Type the key that the certification authority gave you.
Table 94 SECURITY > CERTIFICATES > My Certificates > Create (continued)
LABEL DESCRIPTION