Digi ConnectPort X4 User's Guide Page 233

  • Download
  • Add to my manuals
  • Print
  • Page
    / 271
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 232
Administration from the web interface
233
Tables managed by the X.509 Certificate/Key Management feature
Certificate and key management information is stored in the following database tables:
Security type Table Used to load
X.509 Certificate
Authority/
Certificate
Revocation
CA (Certificate
Authority)
Certificate authority digital certificates. A certificate authority (CA) is a
trusted third party that issues digital certificates for use by other parties.
Digital certificates issued by the CA contain a public key. The
certificate contains information about the individual or organization to
which the public key belongs. A CA verifies digital certificate
applicants' credentials. The CA certificate allows verification of digital
certificates, and the information contained therein, issued by that CA.
CRL (Certificate
Revocation List)
Certificate revocation lists for loaded CAs. A certificate revocation list
(CRL) is a file that contains the serial numbers of digital certificates
issued by a CA which have been revoked, and should no longer be
trusted. Like CAs, CRLs are a vital part of a public key infrastructure
(PKI). The digital certificate of the corresponding CA must be installed
before the CRL can be loaded.
Simple
Certificate
Enrollment
Protocol (SCEP)
SCEP CA
(Certificate
Authority)
SCEP certificate authority digital certificates that have been approved
and issued. Tables are populated using SCEP commands and data is
obtained from a SCEP server, rather than populated by a user.
SCEP Pending
Enrollment
Requests
SCEP certificate requests that are pending approval.
Virtual Private
Networking
(VPN)
VPN Identity VPN identity certificates. Identity certificates and keys allow for IPSec
authentication and secure key exchange with ISAKMP/IKE using RSA
or DSA signatures. The VPN identity certificate must be issued by a
CA trusted by the peer.
VPN Identity Keys VPN RSA or DSA identity private keys.
Secure Sockets
Layer (SSL) and
Transport Layer
Security (TLS)
SSL Identity SSL/TLS identity certificates. A default key is generated automatically
but can be overridden by a user. However, this default key is not secure.
SSL Identity Keys SSL/TLS identity private keys.
SSL Peer SSL/TLS peer certificates.
SSL Revoked Verbatim revoked SSL/TLS certificates.
Secure Shell
(SSHv2)
SSH Host Keys
Table
SSHv2 identity private keys. Used for authentication with SSHv2
clients and secure key exchange. A default 1024-bit DSA key is
generated automatically if none exists when the device boots. There is
no certificate for SSHv2, just private key data.
Page view 232
1 2 ... 228 229 230 231 232 233 234 235 236 237 238 ... 270 271

Comments to this Manuals

No comments