
74 |Onboard ClearPass Guest 3.9 | Deployment Guide
The Key Type drop-down list specifies the type of private key that should be created for the certificate.
You can select one of these options:
1024-bit RSA – not recommended for a certificate authority
2048-bit RSA – recommended for general use
4096-bit RSA – higher security
In the Intermediate Certificate section:
The Digest Algorithm drop-down list allows you to specify which hash algorithm should be used.
Note: MD5 is not recommended for use with certificate authority certificates.
Mark the Generate CA certificate request and invalidate all other certificates check box to confirm
the changes.
Click the Create Certificate Request button to save the settings and generate a new certificate signing
request.
Obtaining a Certificate for the Certificate Authority
The Intermediate Certificate Request page displays the certificate signing request for the certificate
authority’s intermediate certificate. This page is also used to renew the certificate authority’s intermediate
certificate when it is close to expiring.
You can copy the certificate signing request in text format using your Web browser. Use this option when
you can paste the request directly into another application to obtain a certificate.
You can click the Download the current CSR link to download the certificate signing request as a file.
Use this option when you need to provide the certificate signing request as a file to obtain a certificate.
Once you have obtained the certificate, click the Install a signed certificate link to continue configuring
the intermediate certificate authority. See “Installing a Certificate Authority’s Certificate”.
You can also click the Change CA settings link to return to the main Certificate Authority Settings
form. Use this option to switch to a root CA, or to change the name or properties of the intermediate CA and
reissue the certificate signing request.
Using Microsoft Active Directory Certificate Services
Navigate to the Microsoft Active Directory Certificate Services Web page. This page is typically found at
https://yourdomain/certsrv/.
The Welcome page is displayed.
Kommentare zu diesen Handbüchern