Create a certificate request for a VPN Gateway element

You can create a certificate request and sign it using an external certificate authority (CA).

For more details about the product and how to configure features, click Help or press F1.

Steps

  1. Select Secure SD-WAN Configuration.
  2. Select VPN Gateways.
    The gateways are displayed.
  3. Right-click the VPN Gateway element and select More actions > Generate Certificate.
  4. In the Generate Certificate dialog box, enter the certificate information including Common Name, Organization, Organizational Unit, and Country.
    • The target of evaluation generates certificate requests that include a public key, Common Name, Organization, Organizational Unit, Country and device specific information in the form of Subject Alternative Name.
    • The device-specific information includes every IP address, Fully Qualified Domain Name (FQDN), and user FQDN defined as the Phase-1 ID for a VPN endpoint as described in the Define endpoints for VPN Gateway elements section.
    • The target of evaluation performs the asymmetric key generation and includes the public key in the certificate signing request automatically.
  5. Enter the Common Name, Organization, Organizational Unit, Country in the dialog.
    • The device-specific information includes every IP address, Fully Qualified Domain Name (FQDN), and user FQDN defined as the Phase-1 ID for a VPN endpoint as described in the Define endpoints for VPN Gateway elements section.
    • The target of evaluation performs the asymmetric key generation and includes the public key in the certificate signing request automatically.
  6. Select Sign with External Certificate Authority.
  7. Select the Public Key Algorithm according to the requirements of your organization. It can be either RSA or ECDSA.
  8. Select the Signature Algorithm that the certificate authority uses to sign the certificate:
    • For Common Criteria evaluated configuration and RSA, select RSA / SHA-1, RSA / SHA-256, RSA / SHA-384, or RSA / SHA-512.
    • For Common Criteria evaluated configuration and ECDSA, select ECDSA / SHA256, ECDSA / SHA384 or ECDSA / SHA512.
    • For Commercial Solutions for Classified configuration and RSA, select RSA / SHA-384 or RSA / SHA-512.
    • For Commercial Solutions for Classified configuration and ECDSA, select ECDSA / SHA384 or ECDSA / SHA512.
  9. Select the Key Length:
    • For Common Criteria evaluated configuration:
      • RSA: 2048, 3072, or 4096 are allowed
      • ECDSA: 256, 384, or 521 are allowed
    • For Commercial Solutions for Classified configuration:
      • RSA: 3072 or 4096 are allowed
      • ECDSA: Only 384 is allowed
  10. Click OK.
    There might be a slight delay while the certificate request is generated.
    The certificate request is added under the gateway in the gateway list.
  11. (With external certificate authorities only) Right-click the certificate request, select Export Certificate Request, and save it.
    • To generate certificates for a VPN Gateway element, the CA must support PKCS#10 certificate requests in PEM format (Base64 encoding). The signed certificates must also be in the PEM format. It might be possible to convert between formats using, for example, OpenSSL or the certificate tools included in Windows.
    • The CA must be able to copy all attributes from the certificate request into the certificate. In particularly, the X.509 extension Subject Alternative Name must be copied as it is in the request because the value is used for authentication.
  12. When you receive the signed certificate, import it by right-clicking on the certificate request and select Import Certificate.
  13. In the Import Certificate dialog box, click Browse to open the signed certificate file, or select As Text and enter the certificate data. The certificate chain is validated.
  14. Click OK to import the certificate.