Server - importing a ca created ssl certificate – AMX Signature Series NetLinx Integrated Controller NI-3101-SIG User Manual

Page 79

Advertising
background image

NetLinx Security within the Web Server

69

NI-3101-SIG Signature Series NetLinx Integrated Controller

3.

Place your cursor within the certificate text field.

4.

Press the Ctrl + A keys simultaneously on your keyboard (this selects all the text within the field).

5.

Press the Ctrl + C keys simultaneously on your keyboard (this takes the blue selected text within the field
and copies it to your temporary memory/clipboard).

6.

Paste this text into the Submit Request field on the CA’s Retrieve Certificate web page.

7.

Choose to view the certificate response in raw DER format.

8.

Note the Authorization Code and Reference Number (for use in the e-mail submission of the request).

9.

Submit the request.

10.

Paste this certificate text field (copied from steps 4 & 5 above) into your e-mail document and then send
that information to a CA with its accompanying certificate application.

11.

Once the returned CA certificate has been received, follow the procedures outlined in the following
section to import the returned certificate (over a secure connection) to the target Master.

Server - Importing a CA created SSL Certificate

Before importing a CA server certificate:



First

, have a self-generated certificate installed onto the target Master.



Secondly

, enable the SSL security feature from the Enable Security page, to establish a secure

connection to the Master prior to importing the encrypted CA certificate. Refer to theSecurity -
System Level Security page

section on page 39 for more information about enabling SSL security.

1.

Take the returned certificate (signed by the CA and encrypted with new information which makes it
different from the text string that was previously sent) and copy it into the clipboard.

FIG. 52

Export SSL Certificate dialog

Certificate text field

YOU MUST COPY ALL OF THE TEXT within this field, including the -----BEGIN
CERTIFICATE REQUEST-----
and the -----END CERTIFICATE REQUEST-----. This
text in the CA submission must be included to receive a CA-approved certificate.

When a certificate request is generated, you are creating a private key on the Master.
YOU CANNOT REQUEST ANOTHER CERTIFICATE UNTIL THE PREVIOUS
REQUEST HAS BEEN FULFILLED.
Doing so voids any information received from
the previously requested certificate and it becomes nonfunctional if attempted to be
used.

Advertising