Using Certificates with HP-UX IPSec

Using VeriSign Certificates

2.The number of certificates must be equal the number of IPSec systems that will be using certificate-based primary authentication for IKE (such as RSA signatures).

Step 4: Requesting and Receiving Certificates

Each HP-UX IPSec system that will use a certificate-based primary authentication method for IKE must request and get its own certificate before starting the HP-UX IPSec subsystem.

Make sure the number of certificates accommodates the number of HP-UX IPSec systems using VeriSign for IKE primary authentication. Each system needs only one certificate for HP-UX IPSec, even if the system has multiple IP addresses.

To request and receive a VeriSign certificate with HP-UX IPSec:

1.If the VeriSign screen is not already displayed, click the VeriSign tab on the left side of the screen.

Chapter 4

123