Chapter 11 Managing certificates 603

3Click Apply on the toolbar to send the information to the Nortel SNAS 4050. Click Commit on the toolbar to generate the CSR.

If one or more of the CA Request field values are invalid, then an error message appears describing the problem. If all field values are acceptable, then the CSR output appears in the Output Request box.

The private key is created and stored in encrypted form on the Nortel SNAS 4050 using the specified certificate number.

4Save the CSR to a file.

a Click Copy to copy the Output Request text. b Paste the CA request output into a text editor.

c Save the file with a .csr extension. Nortel recommends using a file name that indicates the server on which the certificate is to be used.

5Submit the CSR to a CA such as Entrust or VeriSign.

a In a text editor, open the .csr file you created in step 4.

b Copy the entire CSR, including the -----BEGIN CERTIFICATE REQUEST----- and -----END CERTIFICATE REQUEST----- lines.

c Use your web browser to access the CA web site and follow the online instructions. The process for submitting the CSR varies with each CA. When prompted, paste the CSR as required in the CA online request process. If the CA requires you to identify a server software vendor whose software you used to generate the CSR, specify Apache.

6The CA processes the CSR and returns a signed certificate. Create a backup copy of the certificate.

The certificate is ready to be added into the Nortel SNAS 4050 cluster (see “Importing a certificate or key using the SREM” on page 603).

Importing a certificate or key using the SREM

You can import certificates and private keys into the Nortel SNAS 4050 using TFTP, FTP, SCP, or SFTP. For information about the formats supported for import, see “Key and certificate formats” on page 571.

Nortel Secure Network Access Switch 4050 User Guide

Page 603
Image 603
Nortel Networks 4050 manual Importing a certificate or key using the Srem