McAfee MAP-3300-SWG Product Guide - Page 259

Appliance HTTPS certificate, Certificate Revocation lists (CRLs)

Page 259 highlights

Overview of System features Certificate Management Appliance HTTPS certificate Use this page to specify the contents of a self-signed digital certificate for the appliance. System | Certificate Management | Certificates | Appliance HTTPS Certificate To create a certificate that is signed by a Certification Authority. Certificates typically have a lifetime of several months or years, so they do not need to be managed often. Table 255 Option definitions Option Country [C] Definition Specifies a two-letter code such CN, DE, ES, FR, JP, KR. (See ISO 3166) Default value is US. State or province [ST] Town or city [L] Specifies the location of your organization. Give a full name rather than an abbreviation. Organization [O] Organizational unit [OU] Common name [CN] Email address [ea] Import Specifies the name of your organization such as Example, Inc. Default value is Email and Web Security Appliances. Displays the domain name of your appliance such as server1.example.com Specifies an email address, for example [email protected] When clicked, opens a window where you can specify the file. To import a password-protected certificate, type the passphrase to unlock the private key. The appliance stores the decrypted certificate in a secure internal location. The appliance only verifies the certificate, and makes it available to use, after you click the icon to apply your changes: Export Generate Certificate Signing Request When clicked, opens a window where you can specify a passphrase, then download a file. The file name extension is CRT (base-64 encoded) or P12 (PKCS#12). The certificate is in PEM format. When clicked, opens a window where you can request that the Certificate Signing Request is signed by an Certificate Authority on the appliance or by an external Certificate Authority. The file name extension is CSR. Useful web sites ISO 3166: http://www.iso.org/iso/country_codes.htm Certificate Revocation lists (CRLs) Use the linked pages to import, export and view the Certificate Revocation Lists on your appliance. Contents Installed CRLs CRL updates McAfee Email and Web Security Appliances 5.6.0 Product Guide 259

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336

Appliance HTTPS certificate
Use this page to specify the contents of a self-signed digital certificate for the appliance.
System
|
Certificate Management
|
Certificates
|
Appliance HTTPS Certificate
To create a certificate that is signed by a Certification Authority.
Certificates typically have a lifetime of several months or years, so they do not need to be managed
often.
Table 255
Option definitions
Option
Definition
Country [C]
Specifies a two-letter code such CN, DE, ES, FR, JP, KR. (See ISO 3166)
Default value is
US
.
State or province [ST]
Town or city [L]
Specifies the location of your organization. Give a full name rather than an
abbreviation.
Organization [O]
Specifies the name of your organization such as Example, Inc.
Organizational unit [OU]
Default value is
Email and Web Security Appliances
.
Common name [CN]
Displays the domain name of your appliance such as server1.example.com
Email address [ea]
Specifies an email address, for example [email protected]
Import
When clicked, opens a window where you can specify the file.
To import a password-protected certificate, type the passphrase to unlock the
private key. The appliance stores the decrypted certificate in a secure internal
location.
The appliance only verifies the certificate, and makes it available to use, after
you click the icon to apply your changes:
Export
When clicked, opens a window where you can specify a passphrase, then
download a file. The file name extension is CRT (base-64 encoded) or P12
(PKCS#12). The certificate is in PEM format.
Generate Certificate
Signing Request
When clicked, opens a window where you can request that the Certificate
Signing Request is signed by an Certificate Authority on the appliance or by
an external Certificate Authority. The file name extension is CSR.
Useful web sites
ISO 3166:
Certificate Revocation lists (CRLs)
Use the linked pages to import, export and view the Certificate Revocation Lists on your appliance.
Contents
Installed CRLs
CRL updates
Overview of System features
Certificate Management
McAfee Email and Web Security Appliances 5.6.0 Product Guide
259