Legal Disclaimer: The resource assets in this website may include abbreviated and/or legacy terminology for HPE Aruba Networking products. See www.arubanetworks.com for current and complete HPE Aruba Networking product lines and names.
Creating a New Certificate Authority
The first page of the form is used to create the Onboard Certificate Authority (CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate.) and to configure some basic properties:
Give it a name and description
Specify root CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate., intermediate CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate., local CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate., or Registration Authority Type of Certificate Authority that processes certificate requests. The Registration Authority verifies that requests are valid and comply with certificate policy, and authenticates the user's identity. The Registration Authority then forwards the request to the Certificate Authority to sign and issue the certificate. (RA Router Advertisement. The RA messages are sent by the routers in the network when the hosts send multicast router solicitation to the multicast address of all routers.) mode
Configure the identity, private key The part of a public-private key pair that is always kept private. The private key encrypts the signature of a message to authenticate the sender. The private key also decrypts a message that was encrypted with the public key of the sender., and self-signed certificate attributes
To create an Onboard Certificate Authority, go to Onboard > Certificate Authorities, and then either click the Duplicate link for a Certificate Authority in the list or click the Create new certificate authority link. The initial setup page of the form opens.
Figure 1 Mode Options on the Certificate Authority Settings Form
Figure 2 The Identity Area
|
Field |
Description |
|---|---|
|
Country |
Two-letter ISO country code for your organization. This value forms part of the distinguished name for the certificate. |
|
State |
Full name of the state or province for your organization. This value forms part of the distinguished name for the certificate. |
|
Locality |
Name of the town or city where your organization is located. This value forms part of the distinguished name for the certificate. |
|
Organization |
Name of your organization. This value forms part of the distinguished name for the certificate. |
|
Organizational Unit |
(Optional) Name of your organizational unit (section or division of the organization). This value forms part of the distinguished name for the certificate. |
|
Common Name |
Descriptive name for the certificate. This value is used to identify the certificate as the issuer of other certificates, notably the signing certificate. |
|
Signing Common Name |
(Included for root certificates) Descriptive name for the signing certificate. This value is used to identify the signing certificate as the issuer of client and server certificates from this Certificate Authority. The other identity information in the signing certificate will be the same as for the root certificate. |
|
Email Address |
Contact email address. This email address is included in the root and signing certificates, and provides a way for users of the certificate authority to contact your organization. |
Figure 3 The Private Key and Self-Signed Certificates Areas
Figure 4 The Registration Authority Area
After you have configured the SCEP Simple Certificate Enrollment Protocol. SCEP is a protocol for requesting and managing digital certificates.-RA Router Advertisement. The RA messages are sent by the routers in the network when the hosts send multicast router solicitation to the multicast address of all routers. certificate, you may specify the CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate. to use for TLS Transport Layer Security. TLS is a cryptographic protocol that provides communication security over the Internet. TLS encrypts the segments of network connections above the Transport Layer by using asymmetric cryptography for key exchange, symmetric encryption for privacy, and message authentication codes for message integrity. certificates independently of the CA Certificate Authority or Certification Authority. Entity in a public key infrastructure system that issues certificates to clients. A certificate signing request received by the CA is converted into a certificate when the CA adds a signature generated with a private key. See digital certificate. used for enrollment by using the option in the and fields on the form. For more information, see Configuring General Provisioning Settings.
Was this information helpful?
Great! Thanks for the feedback
Sorry about that! How can we improve it? Send your comments and suggestions!