SSH Communications Security
Index
SSH Home page
Previous Next Up [Contents] [Index]

    Introduction >>
    Configuration >>
        Saving Settings
        Multiple Settings Files
        Loading Settings
        Profile Settings >>
        Global Settings>>
            Appearance
            Font
            Colors
            Messages
            User Keys
            Host Keys
            SSH Accession
            PKI
            Certificates
            Certificate Enrollment Wizard
            LDAP Servers
            PKCS #11
            Configuration
            PKCS #11 Provider
            File Transfer
            Advanced
            Mode
            Firewall
            Security
            Printing
        Customize
    Connecting >>
    Terminal Window >>
    File Transfer >>
    Toolbar Reference >>
    Menu Reference >>
    Advanced Information >>
    Troubleshooting >>
    Appendices >>

Certificate Enrollment Wizard

The Certificate Enrollment wizard (available only in commercial distributions) is used to enroll certificates, i.e. to request a certification authority (CA) to issue a certificate. You can start the wizard by clicking on the Enroll button of the Certificates page of the Settings dialog.

Certificate Enrollment - Start

The first page of the Certificate Enrollment wizard displays information on the enrollment process. The enrollment process will create both a public and a private key. Please note that the process requires the use of Certificate Management Protocol version 2 (CMPv2).


certificateenrollment-start-19.gif
Figure : The start of the enrollment process.

Click the Next button to continue the process.

Certificate Enrollment - Identity

On the Identity page, enter the parameters of the certificate to be issued. You can suggest a Common Name (e.g. John Smith), Organization Unit (like Marketing), Organization (SSH Communications Security Corp.), Country (US) and Email Address (john.smith@ssh.com).


certificateenrollment-identity-20.gif
Figure : Type the parameters of the certificate.

The certification authority can change these fields before issuing the certificate. The Certificate validity period and other parameters are determined by the configuration of the CA software.

Please note that certificate enrollment requiring manual acceptance in the CA software is not supported. You may be able to compensate for this by using PKCS #12 file importing.

Click the Next button to launch the Key Generation Wizard. For more information on the key generation process, see section Key Generation Wizard.

Certificate Enrollment - Firewall

On the Firewall page, you can define the firewall and proxy settings. These fields can be left empty.

  • Firewall

    Type the firewall location in the text field.

  • HTTP proxy

    Type the HTTP proxy location in the text field.

Click the Next button to continue.

Certificate Enrollment - CA

On the CA page, fill in the following fields:

  • CA URL

    Type in the certification authority (CA) address.

  • Discover

    Click the Discover button to attempt automatic detection of available certification authority services and CA certificates. The found CA services will be listed in the text field and can be selected from the drop-down menu.

    Please note that not all systems support the automatic detection functionality.

  • CA Certificate

    Type in the file name of the certificate, or select the file by clicking on the button on the right hand side of the file name field. The Select CA Certificate dialog will open, allowing you to locate the certificate file.

  • View

    Click the View button to display the contents of the current certificate.

  • Retrieve CA Certificates from CA URL

    Select the desired CA URL from the drop-down list and click the Retrieve CA Certificates from CA URL button to retrieve the CA certificates from the selected CA address.

  • Reference Number

    Type in the reference number.

  • Key

    Type in the key information.

Click the Next button to continue.

Certificate Enrollment - Enrollment

On the Enrollment page the actual enrollment takes place. This may take some time (the exact duration depends on the amount of network traffic, among other factors).


certificateenrollment-enrollment-21.gif
Figure : The enrollment in progress.

When the process is finished, click the Finish button to continue.

Previous Next Up [Contents] [Index]


[ Contact Information | Support | Feedback | SSH Home Page | SSH Products ]

Copyright © 2001 SSH Communications Security Corp
All rights reserved.
Copyright Notice