Renew a certificate for the Log Server
You must renew the external certificate before it expires. If the certificate has expired or has been revoked a new certificate request must be generated.
Steps
Example
| Option | Definition |
|---|---|
| Current Certificate | Shows information about the current certificate of the server. Click Export Certificate to export the current certificate. Click Renew Certificate to renew the certificate. |
| Check Revocation | Checks against certificate revocation lists (CRLs or OCSP) whether the certificate of the new connection has been revoked. The certificate must be signed by a valid certificate authority. |
| Ignore Revocation Check Failures if There Are Connectivity Problems | When selected, the server ignores all CRL check failures if the server cannot connect to CRL or OCSP server. This is done based on what is specified in the certificate. |
| Organization (O) (Optional) |
The name of your organization as it appears in the certificate. |
| Organization Unit (OU)
(Optional) |
The name of your department or division as it appears in the certificate. |
| State/Province (ST)
(Optional) |
The name of state or province as it appears in the certificate. |
| Locality (L)
(Optional) |
The name of the city as it appears in the certificate. |
| Common Name (CN) | A common name that includes the name of the Log Server element. |
| Public Key Algorithm (Not editable) |
The algorithm used for the public key. Note: For Log Server certificates, only the ECDSA public key algorithm is supported.
|
| Key Length | The length of the key in bits. Select 384. Note: Key-size parameter of 521 bits is also acceptable if the configuration is not intended
to be compatible with Commercial Solutions for Classified configuration.
|
| Signature Algorithm (Not editable) |
Shows the signature algorithm according to the key length. |
| Subject Alternative Name (DNS) | Name of the Log Server as a fully qualified domain name (FQDN). |
| Generate Certificate Request | Shows the certificate request as text. |
| Export Certificate | Exports the certificate request so that you can sign it using an external certificate authority. |
| Import Signed Certificate | Imports a certificate that has been signed using an external certificate authority. |