Chapter 40 Certificates

"Be careful to not convert a binary file to text during the transfer process. It is easy for this to occur since many programs use text files by default.

40.4Certificate Configuration Screens Summary

This section summarizes how to manage certificates on the ZyWALL.

Use the My Certificate screens to generate and export self-signed certificates or certification requests and import the ZyWALL’s CA-signed certificates.

Use the Trusted Certificates screens to save CA certificates and trusted remote host certificates to the ZyWALL. The ZyWALL will trust any valid certificate that you have imported as a trusted certificate. It will also trust any valid certificate signed by any of the certificates that you have imported as a trusted certificate.

40.5 Verifying a Certificate

Before you import a certificate into the ZyWALL, you should verify that you have the actual certificate. This is especially true of trusted certificates since the ZyWALL also trusts any valid certificate signed by any of the imported trusted certificates.

40.5.1 Checking the Fingerprint of a Certificate on Your Computer

A certificate’s fingerprints are message digests calculated using the MD5 or SHA1 algorithms. The following procedure describes how to check a certificate’s fingerprint to verify that you have the actual certificate.

1Browse to where you have the certificate saved on your computer.

2Make sure that the certificate has a “.cer” or “.crt” file name extension.

Figure 401 Remote Host Certificates

3Double-click the certificate’s icon to open the Certificate window. Click the Details tab and scroll down to the Thumbprint Algorithm and Thumbprint fields.

 

547

ZyWALL USG 1000 User’s Guide