In order for a Subscriber to accept encrypted Distributions from a Distributor, it must have an encrpytion certificate in its security directory that matches a certificate on the Distributor. Encryption certificates are created from Certificate Signing Request (.CSR) files that have been manually copied from the \ZENWORKS\PDS\TED\SECURITY\CSR directory on a Subscriber server to the same directory on the Distributor server.
With this menu option, you can have the Distribution's Distributor sign the CSR files for the applicable Subscriber. Then you must manually copy the signed CSR file back to the Subscriber server, renaming it to the same name used by the Subscriber's normal certificate. Thereafter, the new encrpytion certificate will be used for all Distributions received by the Subscriber, even if they are not encrypted. The key for decrypting an encrypted Distribution is sent by the Distributor only for encrypted Distributions.
If you pass the CSR file over the wire, the Distribution's encryption key could be compromised. Therefore, you must manually copy the CSR files to ensure that the encryption key is kept secure.
Available CSR Files
Displays Subscribers' CSR files on the Distributor's file system that can be signed for the current Distribution. Select one or more files to be signed by the Distributor.
CSR file for Subscriber servers are displayed only if you manually copies the Subscriber's CSR file to the Distributor.
Encrypted Distributions are not supported on Linux or Solaris servers.
Sign
Signs the selected CSR files.
Close
Closes the dialog box when you have finished signing CSR files.