← Prev in month ← Prev in thread

Certificates

From
Rich Salz <>
Date
2005-01-31T20:23:54+00:00
ID
Thread
Certificates
I'm attaching a sample root certificate -- seem okay?

I'm also confused as to how many certificates to create. SSL requires 
the CN to match the hostname, so there's at least one/device for 
everyone (i.e., in most cases two).

The next question is do we have
	an ssl client cert; and
	an ssl server cert; and
	a digital signature cert
or
	a single "omnibus" cert

If we use the "three certs" option, note that the DN's will say things like
	O=DataPower SSLClient, CN=myxs.datapower.com
	O=DataPower Signing, CN=myxs.datapower.com

Right now the "omnibus" cert as the "omnibus" tag in the O field; I'll 
get rid of that.

My plan is to create keys and mail out pkcs#12 files to folks, along 
with "PEM" files.  FYI, I am attaching samples of each kind of client 
cert (sslclient.pem, sslserver.pem, signing.pem, omnibus.pem) and a
sample root cert (root.pem)

I want to grind all these out tonite....  speak quickly. :)

	/r$



-- 
Rich Salz, Chief Security Architect
DataPower Technology                           http://www.datapower.com
XS40 XML Security Gateway   http://www.datapower.com/products/xs40.html
XML Security Overview  http://www.datapower.com/xmldev/xmlsecurity.html
← Prev in month ← Prev in thread