ZyWALL 2 Series User’s Guide

 

 

Table 15-3 My Certificate Create

 

 

 

 

 

LABEL

DESCRIPTION

 

 

 

 

 

 

Create a certification

Select Create a certification request and enroll for a certificate immediately

 

 

request and enroll for

online to have the ZyWALL generate a request for a certificate and apply to a

 

 

a certificate

certification authority for a certificate.

 

 

immediately online

You must have the certification authority’s certificate already imported in the

 

 

 

 

 

 

Trusted CAs screen.

 

 

 

When you select this option, you must select the certification authority’s

 

 

 

enrollment protocol and the certification authority’s certificate from the drop-down

 

 

 

list boxes and enter the certification authority’s server address. You also need to

 

 

 

fill in the Reference Number and Key if the certification authority requires them.

 

 

Enrollment Protocol

Select the certification authority’s enrollment protocol from the drop-down list

 

 

 

box.

 

 

 

Simple Certificate Enrollment Protocol (SCEP) is a TCP-based enrollment

 

 

 

protocol that was developed by VeriSign and Cisco.

 

 

 

Certificate Management Protocol (CMP) is a TCP-based enrollment protocol

 

 

 

that was developed by the Public Key Infrastructure X.509 working group of the

 

 

 

Internet Engineering Task Force (IETF) and is specified in RFC 2510.

 

 

 

 

 

 

CA Server Address

Enter the IP address (or URL) of the certification authority server.

 

 

 

 

 

 

CA Certificate

Select the certification authority’s certificate from the CA Certificate drop-down

 

 

 

list box.

 

 

 

You must have the certification authority’s certificate already imported in the

 

 

 

Trusted CAs screen. Click Trusted CAs to go to the Trusted CAs screen

 

 

 

where you can view (and manage) the ZyWALL's list of certificates of trusted

 

 

 

certification authorities.

 

 

 

 

 

 

Request

When you select Create a certification request and enroll for a certificate

 

 

Authentication

immediately online, the certification authority may want you to include a

 

 

 

reference number and key to identify you when you send a certification request.

 

 

 

Fill in both the Reference Number and the Key fields if your certification

 

 

 

authority uses CMP enrollment protocol. Just fill in the Key field if your

 

 

 

certification authority uses the SECP enrollment protocol.

 

 

Key

Type the key that the certification authority gave you.

 

 

 

 

 

 

Apply

Click Apply to begin certificate or certification request generation.

 

 

 

 

 

 

Cancel

Click Cancel to quit and return to the My Certificates screen.

 

 

 

 

 

Certificates

15-9