10.6 Certificates
An asymmetric cryptosystem is used to encrypt data to be transported in a network, to gen-
erate or check digital signatures and the authenticate users. A key pair consisting of a pub-
lic key and a private key is used to encrypt and decrypt the data.
For encryption the sender requires the public key of the recipient. The recipient decrypts
the data using his private key. To ensure that the public key is the real key of the recipient
and is not a forgery, a so-called digital certificate is required.
This confirms the authenticity and the owner of a public key. It is similar to an official pass-
port in that it confirms that the holder of the passport has certain characteristics, such as
gender and age, and that the signature on the passport is authentic. As there is more than
one certificate issuer, e.g. the passport office for a passport, and as such certificates can
be issued by several different issuers and in varying qualities, the trustworthiness of the is-
suer is extremely important. The quality of a certificate is regulated by the German Signa-
ture Act or respective EU Directives.
Certification authorities that issue so-called qualified certificates are organised in a hier-
archy with the Federal Network Agency as the higher certifying authority. The structure and
content of a certificate are stipulated by the standard used. X.509 is the most important and
the most commonly use standard for digital certificates. Qualified certificates are personal
and extremely trustworthy.
Digital certificates are part of a so-called Public Key Infrastructure (PKI). PKI refers to a
system that can issue, distribute and check digital certificates.
Certificates are issued for a specific period, usually one year, i.e. they have a limited valid-
ity period.
Your device is designed to use certificates for VPN connections and for voice connections
over Voice over IP.
10.6.1 Certificate List
A list of all existing certificates is displayed in the System
Management->Certificates->Certificate List menu.
10.6.1.1 Edit
Click the
icon to display the content of the selected object (key, certificate, or request).
Funkwerk Enterprise Communications GmbH
10 System Management
bintec Rxxx2/RTxxx2
109