Directory Servers

This screen displays a summary list of directory servers (that contain lists of valid and revoked certificates) that have been saved into the Prestige.

If you decide to have the Prestige check incoming certificates against the issuing certification authority's list of revoked certificates, the Prestige first checks the server(s) listed in the CRL Distribution Points field of the incoming certificate. If the certificate does not list a server or the listed server is not available, the Prestige checks the servers listed here.

 

Label

Description

Certificate Name

This field displays the identifying name of this certificate. If you want to change the name, type up to 31 characters to identify this certificate. You may use any character (not including spaces).

Property

This field is only applicable with self-signed certificates.

Select this check box to have the Prestige use this certificate to sign the trusted remote host certificates that you import to the Prestige.

If this check box is already selected, you cannot clear it in this screen, you must select this check box in another self-signed certificate's details screen. This automatically clears the check box in the details screen of the certificate that was previously set to sign the imported trusted remote host certificates.

Certification Path

Click the Refresh button to have this read-only text box display the hierarchy of certification authorities that validate the certificate (and the certificate itself).

If the issuing certification authority is one that you have imported as a trusted certification authority, it may be the only certification authority in the list (along with the certificate itself). If the certificate is a self-signed certificate, the certificate itself is the only one in the list. The Prestige does not trust the certificate and displays "Not trusted" in this field if any certificate on the path has expired or been revoked.

Refresh

Click Refresh to display the certification path.

Certificate Information

These read-only fields display detailed information about the certificate.

Type

This field displays general information about the certificate. "CA-signed" means that a Certification Authority signed the certificate. "Self-signed" means that the certificate's owner signed the certificate (not a certification authority). "X.509" means that this certificate was created and signed according to the ITU-T X.509 recommendation that defines the formats for public-key certificates.

Version

This field displays the X.509 version number.

Serial Number

This field displays the certificate's identification number given by the certification authority or generated by the Prestige.

Subject

This field displays information that identifies the owner of the certificate, such as Common Name (CN), Organizational Unit (OU), Organization (O) and Country (C).

Issuer

This field displays identifying information about the certificate's issuing certification authority, such as Common Name, Organizational Unit, Organization and Country.

With self-signed certificates, this is the same as the Subject Name field.

Signature Algorithm

This field displays the type of algorithm that was used to sign the certificate. The Prestige uses rsa-pkcs1-sha1 (RSA public-private key encryption algorithm and the SHA1 hash algorithm). Some certification authorities may use ras-pkcs1-md5 (RSA public-private key encryption algorithm and the MD5 hash algorithm).

Valid From

This field displays the date that the certificate becomes applicable. The text displays in red and includes a "Not Yet Valid!" message if the certificate has not yet become applicable.

Valid To

This field displays the date that the certificate expires. The text displays in red and includes an "Expiring!" or "Expired!" message if the certificate is about to expire or has already expired.

Key Algorithm

This field displays the type of algorithm that was used to generate the certificate's key pair (the Prestige uses RSA encryption) and the length of the key set in bits (1024 bits for example).

Subject Alternative Name

This field displays the certificate owner's IP address (IP), domain name (DNS) or e-mail address (EMAIL).

Key Usage

This field displays for what functions the certificate's key can be used. For example, "DigitalSignature" means that the key can be used to sign certificates and "KeyEncipherment" means that the key can be used to encrypt text.

Basic Constraint

This field displays general information about the certificate. For example, "Subject Type=CA" means that this is a certification authority's certificate and "Path Length Constraint=1" means that there can only be one certification authority in the certificate's path.

MD5 Fingerprint

This is the certificate's message digest that the Prestige calculated using the MD5 algorithm.

SHA1 Fingerprint

This is the certificate's message digest that the Prestige calculated using the SHA1 algorithm.

Certificate in PEM (Base-64) Encoded Format

This read-only text box displays the certificate or certification request in Privacy Enhanced Mail (PEM) format. PEM uses 64 ASCII characters to convert the binary certificate into a printable form.

You can copy and paste a certification request into a certification authority's web page, an e-mail that you send to the certification authority or a text editor and save the file on a management computer for later manual enrollment.

You can copy and paste a certificate into an e-mail to send to friends or colleagues or you can copy and paste a certificate into a text editor and save the file on a management computer for later distribution (via floppy disk for example).

BackClick Back to return to the previous screen.

Export

Click this button and then OK in the File Download screen. The Save As screen opens, browse to the location that you want to use and click Save.

Apply

Click Apply to save your changes back to the Prestige. You can only change the name, except in the case of a self-signed certificate which you can also set to be the default self-signed certificate that signs the imported trusted remote host certificates.

Cancel

Click Cancel to start configuring this screen again.