How to create a Certificate Signing Request (CSR) and import a signed certificate on SMA 1000 series appliance?
03/26/2020 27 6072
This article describes the basic process that needs to be followed to get a signed certificate on the SMA 1000 series appliance. Certificate Authority (CA) signed Certificates are pivotal for ensuring a secure , encrypted and authentic SSL/TLS connection. While generating a CSR , you generate a private-public key pair. The private key never leaves the appliance/server and the public key is submitted to the CA in the form of CSR. The CA signs this CSR with a digital signature of its own which makes the certificate valid and trusted throughout the Internet.
-Go to Appliance management UI and navigate to System Configuration > SSL Certificates > SSL Settings > SSL Certificates > Certificate Signing Requests tab and click on "Add new"
-Fill in the details accordingly and click on "Save"
-You will see the CSR contents like in the image below. Copy it and submit to your CA
-The Certificate Authority will provide you with a Signed certificate (in PKCS#7 or X509 format)
--Click on the "Process CSR Response" section and import the certificate that was provided by the CA
-Save it and Apply Pending Changes.
In case you do not want to create a CSR on the appliance please go to System Configuration > SSL Certificates > SSL Settings > SSL Certificates > General Tab and click on "Add new". In this case since the CSR is not generated on the appliance so you will have to import the certificate and its private key to the appliance. The certificate must be in PKCS#12 format.
NOTE: The certificate import should not need a reboot or a restart of services but in order to make the certificate "Active" , restart is done automatically.
The option would be you can copy the text without any extra spaces inside "Certificate Text" and then save it.
NOTE: A common error when processing a CSR response or importing a new certificate is the indication that the chain is incomplete. This error is an indication that either the CSR response or certificate does not include the intermediate and root certificates. To clear this issue import the CA root and intermediate certificates into the CA certificates section before processing the CSR or importing the certificate again.