Konica Minolta C300i bizhub C360i/C300i/C250i Security Operations User Manual - Page 86

Setting for the IPsec communication certificate

Page 86 highlights

2.21 Setting for the IPsec communication certificate 2 2.21 Setting for the IPsec communication certificate Logging on to the administrator mode allows the machine to set a certificate required for IPsec communication. 2.21.1 Introducing the device certificate for IPsec communication To perform IPsec communication using the digital signature certificate, the certificate for the machine issued by a reliable CA (certification authority) is needed. When the certificate is expired, obtain the certificate again and specify it as the device certificate of the machine. 0 The Web Connection can be used for this setting. 0 For the procedure to access the administrator mode, see page 2-2. 0 Do not leave the machine with the setting screen of administrator mode left shown on the display. If it is absolutely necessary to leave the machine, be sure first to log off from the administrator mode. 0 Use an RSA key length of 2048 bits and SHA-256 for the IPsec certificate to be introduced to the ma- chine. 1 Call the administrator mode. 2 Click [Security] - [PKI Settings] - [Device Certificate Setting]. 3 Click [New Registration]. 4 Select [Request a Certificate], and click [OK]. 5 Enter information necessary for issuing the certificate and click [OK]. Certificate issuance request data to be sent to the certification authority is created. 6 Click [Save]. % Save the certificate issuance request data in the computer as a file. 7 Send the certificate issuance request data to the authority. 8 After the examination at the authority, the data is returned. Register it with the machine. % Append the text data sent from the CA (certification authority) in [Security] - [PKI Settings] - [Device Certificate Setting] - [Setting] - [Install a Certificate] in the administrator mode, and click [Install]. 2.21.2 Deleting the IPsec communication device certificate An IPsec communication device certificate that has no longer been used can be deleted. 0 The Web Connection can be used for this setting. 0 For the procedure to access the administrator mode, see page 2-2. 0 Do not leave the machine with the setting screen of administrator mode left shown on the display. If it is absolutely necessary to leave the machine, be sure first to log off from the administrator mode. 0 If multiple device certificates are introduced, the device certificate specified as a default cannot be de- leted. Designate another certificate as a default to delete the original default certificate. 0 If only one device certificate is introduced, the certificate specified as a default can be deleted. 1 Call the administrator mode. 2 Click [Security] - [PKI Settings] - [Device Certificate Setting]. 3 Select the certificate to be deleted and click [Setting]. 4 Select [Remove a Certificate] and click [OK]. 5 Details on the certificate to be discarded are displayed on the screen. If no problem is found, click [OK]. bizhub C360i/C300i/C250i/C036DNi/C030DNi/C025DNi 2-66

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106

bizhub C360i/C300i/C250i/C036DNi/C030DNi/C025DNi
2-66
2.21
Setting for the IPsec communication certificate
2
2.21
Setting for the IPsec communication certificate
Logging on to the administrator mode allows the machine to set a certificate required for IPsec communica-
tion.
2.21.1
Introducing the device certificate for IPsec communication
To perform IPsec communication using the digital signature certificate, the certificate for the machine issued
by a reliable CA (certification authority) is needed.
When the certificate is expired, obtain the certificate again and specify it as the device certificate of the ma-
chine.
0
The
Web Connection
can be used for this setting.
0
For the procedure to access the administrator mode, see page 2-2.
0
Do not leave the machine with the setting screen of administrator mode left shown on the display. If it
is absolutely necessary to leave the machine, be sure first to log off from the administrator mode.
0
Use an RSA key length of 2048 bits and SHA-256 for the IPsec certificate to be introduced to the ma-
chine.
1
Call the administrator mode.
2
Click [Security] - [PKI Settings] - [Device Certificate Setting].
3
Click [New Registration].
4
Select [Request a Certificate], and click [OK].
5
Enter information necessary for issuing the certificate and click [OK].
Certificate issuance request data to be sent to the certification authority is created.
6
Click [Save].
%
Save the certificate issuance request data in the computer as a file.
7
Send the certificate issuance request data to the authority.
8
After the examination at the authority, the data is returned. Register it with the machine.
%
Append the text data sent from the CA (certification authority) in [Security] - [PKI Settings] - [Device
Certificate Setting] - [Setting] - [Install a Certificate] in the administrator mode, and click [Install].
2.21.2
Deleting the IPsec communication device certificate
An IPsec communication device certificate that has no longer been used can be deleted.
0
The
Web Connection
can be used for this setting.
0
For the procedure to access the administrator mode, see page 2-2.
0
Do not leave the machine with the setting screen of administrator mode left shown on the display. If it
is absolutely necessary to leave the machine, be sure first to log off from the administrator mode.
0
If multiple device certificates are introduced, the device certificate specified as a default cannot be de-
leted. Designate another certificate as a default to delete the original default certificate.
0
If only one device certificate is introduced, the certificate specified as a default can be deleted.
1
Call the administrator mode.
2
Click [Security] - [PKI Settings] - [Device Certificate Setting].
3
Select the certificate to be deleted and click [Setting].
4
Select [Remove a Certificate] and click [OK].
5
Details on the certificate to be discarded are displayed on the screen. If no problem is found, click [OK].