12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Managing the Certificate AuthorityManagement Server CA CertificatePrint a copy of the Management Server CA certificate to the screen. You can manually save it tothe client. You can use this for client access to the authentication web page.Generate a New CertificateType a subject common name, organizational unit, password, and certificate lifetime to make anew certificate.- For MUVPN users, the common name must agree with the user name of the remote user.- For Firebox® users, the common name must agree with the Firebox identifying information(normally, its IP address).- For a generic certificate, the common name is the name of the user.NoteType the organizational unit only if you make certificates for MUVPN users. Do not use this for othertypes of VPN tunnels. The unit name must appear in this format:GW:where is the value of config.watchguard.id in the configuration file of the gatewayFirebox.Find and Manage CertificatesGive the serial number, common name, or organizational unit of a certificate to find in thedatabase. Also, as an alternative to a special certificate, you can make sure that only active,revoked, or expired certificates are found. The results of the search appear on the ListCertificates page.List and Manage CertificatesSee a list of certificates that are in the database. Select the certificates to publish, revoke, putback, or remove. For information about how to manage certificates, see the section that follows.Upload Certificate RequestUse this page to sign a certificate request from a different device. Type in the common nameand organizational unit of the subject and click Browse to find the CSR (Certificate SigningRequest) file.Publish a Certificate Revocation List (CRL)Make the CA publish the CRL to all clients with current certificates. A Managed Firebox clientcannot create a VPN tunnel if it uses a certificate that is on the CRL to authenticate.Managing certificates with the CA ManagerYou use the List and Manage Certificates page to publish, revoke, put back, or remove certificates:1 From the List and Manage Certificates page, select the serial number of the certificate to change.2 From the Choose Action drop-down list, select one of the alternatives, and then select GO:Revoke CheckedRevokes a certificate. Managed Firebox clients will not see that the CRL was revoked until theCRL is published.Reinstate CheckedPuts back a certificate that was revoked before.Destroy CheckedRemoves a certificate.<strong>User</strong> <strong>Guide</strong> 223

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!