← Prev in month
← Prev in thread
Certificates
I'm attaching a sample root certificate -- seem okay? I'm also confused as to how many certificates to create. SSL requires the CN to match the hostname, so there's at least one/device for everyone (i.e., in most cases two). The next question is do we have an ssl client cert; and an ssl server cert; and a digital signature cert or a single "omnibus" cert If we use the "three certs" option, note that the DN's will say things like O=DataPower SSLClient, CN=myxs.datapower.com O=DataPower Signing, CN=myxs.datapower.com Right now the "omnibus" cert as the "omnibus" tag in the O field; I'll get rid of that. My plan is to create keys and mail out pkcs#12 files to folks, along with "PEM" files. FYI, I am attaching samples of each kind of client cert (sslclient.pem, sslserver.pem, signing.pem, omnibus.pem) and a sample root cert (root.pem) I want to grind all these out tonite.... speak quickly. :) /r$ -- Rich Salz, Chief Security Architect DataPower Technology http://www.datapower.com XS40 XML Security Gateway http://www.datapower.com/products/xs40.html XML Security Overview http://www.datapower.com/xmldev/xmlsecurity.html
← Prev in month
← Prev in thread