Lenovo RD220 User Guide - Page 46

SSL server certificate management, Generating a self-signed certificate

Page 46 highlights

to generate a certificate-signing request. You must then send the certificate-signing request to a certificate authority and make arrangements to procure a certificate. When the certificate is received, it is then imported into the IMM through the Import a Signed Certificate link, and you can enable SSL. The function of the certificate authority is to verify the identity of the IMM. A certificate contains digital signatures for the certificate authority and the IMM. If a well-known certificate authority issues the certificate or if the certificate of the certificate authority has already been imported into the Web browser, the browser can validate the certificate and positively identify the IMM Web server. The IMM requires a certificate for the secure Web server and one for the secure LDAP client. Also, the secure LDAP client requires one or more trusted certificates. The trusted certificate is used by the secure LDAP client to positively identify the LDAP server. The trusted certificate is the certificate of the certificate authority that signed the certificate of the LDAP server. If the LDAP server uses self-signed certificates, the trusted certificate can be the certificate of the LDAP server itself. Additional trusted certificates must be imported if more than one LDAP server is used in your configuration. SSL server certificate management The SSL server requires that a valid certificate and corresponding private encryption key be installed before SSL is enabled. Two methods are available for generating the private key and required certificate: using a self-signed certificate and using a certificate that is signed by a certificate authority. If you want to use a self-signed certificate for the SSL server, see "Generating a self-signed certificate." If you want to use a certificate-authority-signed certificate for the SSL server, see "Generating a certificate-signing request." Generating a self-signed certificate To generate a new private encryption key and self-signed certificate, complete the following steps: 1. In the navigation plane, click Security. 2. In the SSL Server Configuration for Web Server area, make sure that the setting is Disabled. If it is not disabled, select Disabled and then click Save. Notes: a. The IMM must be restarted before the selected value (Enabled or Disabled) takes effect. b. Before you can enable SSL, a valid SSL certificate must be in place. c. To use SSL, you must configure a client Web browser to use SSL3 or TLS. Older export-grade browsers with only SSL2 support cannot be used. 3. In the SSL Server Certificate Management area, select Generate a New Key and a Self-signed Certificate. 4. Type the information in the required fields and any optional fields that apply to your configuration. For a description of the fields, see "Required certificate data" on page 41. After you finish typing the information, click Generate Certificate. Your new encryption keys and certificate are generated. This process might take several minutes. You see confirmation if a self-signed certificate is installed. Generating a certificate-signing request To generate a new private encryption key and certificate-signing request, complete the following steps: 40 Integrated Management Module: User Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120

to generate a certificate-signing request. You must then send the certificate-signing
request to a certificate authority and make arrangements to procure a certificate.
When the certificate is received, it is then imported into the IMM through the
Import a Signed Certificate
link, and you can enable SSL.
The function of the certificate authority is to verify the identity of the IMM. A
certificate contains digital signatures for the certificate authority and the IMM. If a
well-known certificate authority issues the certificate or if the certificate of the
certificate authority has already been imported into the Web browser, the browser
can validate the certificate and positively identify the IMM Web server.
The IMM requires a certificate for the secure Web server and one for the secure
LDAP client. Also, the secure LDAP client requires one or more trusted certificates.
The trusted certificate is used by the secure LDAP client to positively identify the
LDAP server. The trusted certificate is the certificate of the certificate authority that
signed the certificate of the LDAP server. If the LDAP server uses self-signed
certificates, the trusted certificate can be the certificate of the LDAP server itself.
Additional trusted certificates must be imported if more than one LDAP server is
used in your configuration.
SSL server certificate management
The SSL server requires that a valid certificate and corresponding private
encryption key be installed before SSL is enabled. Two methods are available for
generating the private key and required certificate: using a self-signed certificate
and using a certificate that is signed by a certificate authority. If you want to use a
self-signed certificate for the SSL server, see “Generating a self-signed certificate.”
If you want to use a certificate-authority-signed certificate for the SSL server, see
“Generating a certificate-signing request.”
Generating a self-signed certificate
To generate a new private encryption key and self-signed certificate, complete the
following steps:
1.
In the navigation plane, click
Security
.
2.
In the
SSL Server Configuration for Web Server
area, make sure that the
setting is
Disabled
. If it is not disabled, select
Disabled
and then click
Save
.
Notes:
a.
The IMM must be restarted before the selected value (
Enabled
or
Disabled
)
takes effect.
b.
Before you can enable SSL, a valid SSL certificate must be in place.
c.
To use SSL, you must configure a client Web browser to use SSL3 or TLS.
Older export-grade browsers with only SSL2 support cannot be used.
3.
In the
SSL Server Certificate Management
area, select
Generate a New Key
and a Self-signed Certificate
.
4.
Type the information in the required fields and any optional fields that apply to
your configuration. For a description of the fields, see “Required certificate
data” on page 41. After you finish typing the information, click
Generate
Certificate
. Your new encryption keys and certificate are generated. This
process might take several minutes. You see confirmation if a self-signed
certificate is installed.
Generating a certificate-signing request
To generate a new private encryption key and certificate-signing request, complete
the following steps:
40
Integrated Management Module: User Guide