
Version 5.6 87 November 2008
SIP User's Manual 3. Web-Based Management
3. In the 'Subject Name' field, enter the DNS name, and then click Generate CSR. A
textual certificate signing request that contains the SSL device identifier is displayed.
4. Copy this text and send it to your security provider. The security provider (also known
as Certification Authority or CA) signs this request and then sends you a server
certificate for the device.
5. Save the certificate to a file (e.g., cert.txt). Ensure that the file is a plain-text file
containing the ‘BEGIN CERTIFICATE’ header, as shown in the example of a Base64-
Encoded X.509 Certificate below:
-----BEGIN CERTIFICATE-----
MIIDkzCCAnugAwIBAgIEAgAAADANBgkqhkiG9w0BAQQFADA/MQswCQYDVQQGEwJGUj
ETMBEGA1UEChMKQ2VydGlwb3N0ZTEbMBkGA1UEAxMSQ2VydGlwb3N0ZSBTZXJ2ZXVy
MB4XDTk4MDYyNDA4MDAwMFoXDTE4MDYyNDA4MDAwMFowPzELMAkGA1UEBhMCRlIxEz
ARBgNVBAoTCkNlcnRpcG9zdGUxGzAZBgNVBAMTEkNlcnRpcG9zdGUgU2VydmV1cjCC
ASEwDQYJKoZIhvcNAQEBBQADggEOADCCAQkCggEAPqd4MziR4spWldGRx8bQrhZkon
WnNm`+Yhb7+4Q67ecf1janH7GcN/SXsfx7jJpreWULf7v7Cvpr4R7qIJcmdHIntmf7
JPM5n6cDBv17uSW63er7NkVnMFHwK1QaGFLMybFkzaeGrvFm4k3lRefiXDmuOe+FhJ
gHYezYHf44LvPRPwhSrzi9+Aq3o8pWDguJuZDIUP1F1jMa+LPwvREXfFcUW+w==
-----END CERTIFICATE-----
6. Set the parameter 'Secured Web Connection (HTTPS)' to 'HTTPS Only' (0) (refer to
''Configuring the General Security Settings'' on page 90) to e
nsure you have a method
of accessing the device in case the new certificate doesn’t work. Restore the previous
setting after testing the configuration.
7. In the 'Certificates Files' group, click the Browse button corresponding to 'Send Server
Certificate...', navigate to the cert.txt file, and then click Send File.
8. When the loading of the certificate is complete, save the configuration (refer to ''Saving
Configuration'' on page 209) an
d restart the device; the Web interface uses the
provided certificate.
Notes:
• The certificate replacement process can be repeated when necessary
(e.g., the new certificate expires).
• It is possible to use the IP address of the device (e.g., 10.3.3.1) instead of
a qualified DNS name in the Subject Name. This is not recommended
since the IP address is subject to changes and may not uniquely identify
the device.
• The server certificate can also be loaded via ini file using the parameter
HTTPSCertFileName.
Comentários a estes Manuais