Obtaining a Certificate from an External CA


Requesting the CSR

  1. In the browser-based management tool, click Home > Certificate Maintenance > Create.

  2. Type an appropriate name for the certificate, as explained in Naming Certificates.

  3. Type an appropriate subject name, as explained in Naming Certificates.

  4. Click the Signature Algorithm drop-down list > select the algorithm you want to use (SHA-1 or MD-5).

  5. Click the RSA Key Size drop-down list > select the RSA key size that you want to use.

    You cannot select a key size larger than the maximum key size on the Appliance.

  6. Click Use External Certificate Authority.

  7. If you are requesting a VeriSign certificate, check the VeriSign CA checkbox. Otherwise, leave the box unchecked.

  8. If desired, type a name for your organization or division.

    This is commonly referred to as the Organizational Unit and is used to differentiate organizational divisions or to describe departments or divisions.

  9. Type the city or town where your organization does business.

    This is commonly referred to as the Locality.

  10. Type the unabbreviated name of the state or province where the organization does business.

    This is commonly referred to as the State.

  11. Type the ISO country code for the country where the organization does business.

    This is commonly referred to as the Country and must be a valid, two-character ISO country code.

  12. Click OK.

  13. Look at the Action and Status fields.

    The Action field should have red arrows on the left and the word Request displayed on a green background. The Status should be Building.

    The red arrows and green background indicate that you need to click Apply.

  14. Click Apply.

    If any errors occur during the certificate creation process, they are displayed in the Error field on a red background.

  15. If an error occurs, click Modify.

  16. In the Modify Certificate dialog box, make the changes necessary to resolve the errors > click OK.

  17. Click Apply and repeat the modification process until the Status field displays the words CSR in Progress on a yellow background.


Sending the CSR

  1. To open a new browser window that displays the CSR contents, click View CSR.

  2. Select and copy the complete CSR text into your computer's clipboard. Internet Explorer and other browsers sometimes combine them with the CSR text that is in between. Clicking the browser refresh/reload button will often fix the problem. If it doesn't, simply insert appropriate carriage returns during the next step. After you have copied the text, you can close that browser window.

  3. Paste the CSR text from the clipboard to the e-mail message or HTML form as required by your CA.

    The method for sending the CSR will vary, depending on the authority. VeriSign, for example, uses a web page interface.

    IMPORTANT:  The header and trailer must be on lines separate from the body of the CSR.

    The header line will be similar to the following:

    ----- BEGIN NEW CERTIFICATE REQUEST-----

    The trailer line will be similar to the following:

    -----END NEW CERTIFICATE REQUEST-----

    If required, you must use hard returns to separate these two lines from the body of the CSR.

  4. Wait for the certificate to be returned from the external CA.


Storing the Certificate

After the external CA responds with the certificate, do the following:

  1. In the browser-based tool, click Home > Certificate Maintenance > the name of the certificate you want to store > Store Certificate.

  2. In the Store Certificates dialog box, paste the CA certificate in the CA Certificate Contents box.

    NOTE:   If you requested a VeriSign certificate and you checked the VeriSign box in Step 7, the CA Certificate Contents box is grayed out. You will not need to paste the VeriSign CA certificate because VeriSign certificates are already stored on the appliance.

  3. Paste your newly issued certificate in the Server Certificate Contents box.

  4. Click Create.

  5. Look at the Action and Status fields.

    The Action field should have red arrows on the left and the word Create displayed on a green background. The Status should be CSR in Process.

    The red arrows and green background indicate that you need to click Apply.

  6. Click Apply.

    If any errors occur during the certificate creation process, they are displayed in the Error field on a red background.

  7. If an error occurs, click Store Certificate.

  8. In the Store Certificate dialog box, make sure the correct certificates are pasted in the boxes > click OK.

  9. Click Apply and repeat the modification process until the Status field displays the words Active on a green background.