Panel | |||
---|---|---|---|
In this section:
|
...
|
The
Spacevars | ||
---|---|---|
|
...
supports generating and installing RSA key pairs, and
...
then generating Certificate Signing Request (CSR) on
...
the
Spacevars | ||
---|---|---|
|
Spacevars | ||
---|---|---|
|
...
provides
...
enhanced security since the private key never leaves the
application. Spacevars 0 product
...
SBC supports three types of certificates:
Multiexcerpt include | ||||
---|---|---|---|---|
|
...
Include Page Max_Nbr_TLS_Certs Max_Nbr_TLS_Certs
...
Caption | ||||
---|---|---|---|---|
| ||||
To edit any of the Certificate in the list, click the radio button next to the specific Certificate name.
Caption | ||||
---|---|---|---|---|
| ||||
The Edit Selected Certificate window is displayed below.
Caption | ||||
---|---|---|---|---|
| ||||
Make the required changes and click Save at the right hand bottom of the panel to save the changes made.
...
Perform the following steps to create a new Certificate.
Caption | ||||
---|---|---|---|---|
| ||||
...
...
Caption | ||||
---|---|---|---|---|
| ||||
The following fields are displayed:
Caption | ||||
---|---|---|---|---|
| ||||
Complete the fields using the table below for guidance.
Parameter | Description |
---|---|
Name | Specifies the name of the certificate. |
State | Enable this flag to enable the use of the certificate once it has been installed. The options are: |
...
|
...
| |
File Name |
|
...
– Enter the |
...
filename and set state to "enabled" to install the certificate. | |
Pass Phrase | Specifies the Pass-phrase to decrypt RSA private key in PKCS12 file. |
Type | Use this object to specify the type of certificate: |
...
|
...
|
...
|
On the SBC main screen, go to Configuration > Security Configuration >PKI > Certificate.
The Certificate window displays.
Perform the following steps to edit a Certificate in the list.
...
Perform the following steps to copy a created Certificate, and to make any minor changes
...
.
...
...
Caption | ||||
---|---|---|---|---|
| ||||
...
...
Caption | ||||
---|---|---|---|---|
| ||||
...
...
0 | Figure |
---|---|
1 | Security Configuration - PKI - Certificate Highlighted |
...
Perform the following steps to delete a Certificate.
...
0 | Figure |
---|---|
1 | Security Configuration - PKI - Certificate Delete Confirmation |
...
...
Click the radio button next to the specific Certificate to highlight the row.
The Certificate Command window
...
displays at the bottom of the screen.
Caption | ||||
---|---|---|---|---|
|
...
...
Command options:
...
...
...
When you select the certificate command Generate CSR, and click Select, the following dialog displays:
Caption | ||||
---|---|---|---|---|
|
...
...
...
SBC supports SAN Support from 4.0.2 release.
The Subjective Alternative Name (SAN) is an X509 version 3 extension that allows an SSL certificate to specify multiple names that the certificate should match. This allows you to secure a large number of domains with only one certificate. Even when SAN contains eMail addresses, IP Addresses, Regular DNS Host Name, and so on, SBC now supports only DNS Host Name.
The Lync 2013 video call requires a unique FQDN to identify SBC. This FQDN is not the same as the one used by the Mediation server for regular Audio Only calls. Since SBC now requires 2 FQDN to place bothe Audio and Video calls on Lync using static route from Lync FE, SBC local certificate must contain both the FQDNs for CN and SAN. This is required for a successful TLS connection set up between Lync and SBC.
To continue, select "Key Size", enter "Csr Sub" name and click generateCSR. The Certificate Signing Request (CSR) is generated similar to the example below:
Caption | ||||
---|---|---|---|---|
|
...
Click
...
OK to exit.
When you select the certificate command Import Cert, and click Select the following dialog displays:
Caption | ||||
---|---|---|---|---|
|
...
Note |
---|
You can cut-and-paste the returned certificate content from Certificate Authority (CA) in the |
To continue, enter "Cert Content" description and click importCert.
Once the certificate is successfully imported, return to the Certificate screen and change State to "enabled" to enable the certificate.
The following are the Certificate parameters:
Caption | ||||
---|---|---|---|---|
|
...
|
...
|
...
|
...
|
...
|
...
...
This field is available from 4.0.2 release.
The Retrieve Cert Content command extracts the complete certificate information including the serial number and the validity period.
On the Certificate Commands window, select Retrieve Cert Content
command.
Note |
---|
You cannot view the Private Key |
...
Caption | ||||
---|---|---|---|---|
| ||||
in the retrieved certificate content. |
The following window
...
displays:
Click retrieveCertContent to proceed and to view the complete information of the certificate.
The Message window
...
displays, providing all the information of the certificate.
Note |
---|
This certificate content is an ASCII representation of X.509 format. |
...
0 | Figure |
---|---|
1 | Retrieve Cert Content Message |
...
...
...
Pagebreak |
---|