NetLinx Security within the Web Server

11.Once the returned CA certificate has been received, follow the procedures outlined in the following section to import the returned certificate (over a secure connection) to the target Master.

Server - Importing a CA created SSL Certificate

Before importing a CA server certificate:

First, have a self-generated certificate installed onto the target Master.

Secondly, enable the SSL security feature from the Enable Security page, to establish a secure connection to the Master prior to importing the encrypted CA certificate. Refer to theSecurity

-System Level Security page section on page 49 for more information about enabling SSL security.

1.Take the returned certificate (signed by the CA and encrypted with new information which makes it different from the text string that was previously sent) and copy it into the clipboard.

2.Navigate to the Server Certificate page by clicking System Settings > Manage System > Server > Import SSL Certificate to open the Import Certificate page (FIG. 51).

Certificate text field

FIG. 51 Import SSL Certificate dialog

3.Place the cursor within the empty window and paste the raw text data (in its entirety) into the field.

4.Click the Update button to enter the new encrypted certificate information and save it to the Master.

Once a certificate has been purchased from an external CA and then installed onto a specific Master, DO NOT regenerate the certificate or alter its properties (example: bit length, city, etc.). If the purchased certificate is regenerated, it becomes invalid.

A certificate consists of two different Keys:

Master Key is generated by the Master and is incorporated into the text string sent to the CA during a certificate request. It is specific to a particular request made on a specific Master.

Public Key is part of the text string that is returned from the CA as part of an approved SSL Server Certificate. This public key is based off the submitted Master key from the original request.

Regenerating a previously requested and installed certificate invalidates the previously purchased certificate because the Master Key has been changed.

NI-3101-SIG Signature Series NetLinx Integrated Controller

85

 

 

Page 91
Image 91
AMX NI-3101-SIG manual Server Importing a CA created SSL Certificate, Before importing a CA server certificate