11 Menu Authentication
Securepoint 10
Securepoint
Security Solutions
163
11.3 Certificates
The appliance uses certificates to authenticate users which connect via VPN. The certificate
proves the users identity and contains a digital signature and statements about the owner.
Certificates are signed by a Certification Authority (CA) to guarantee the genuineness of the
certificate. Normally the CA is a third independent and trustable instance. You can create a
CA yourself to sign the certificates you have generated. The signed certificates will be distri-
buted to the users which connect to the local net via VPN. The signature assures that the
certificates are created by the firewall and not by anybody else.
For a complete authentication, not only the remote station needs a certificate but also the
firewall itself. You have to create one certificate for the firewall and one certificate for each
external user.
You can import external certificates given in PEM format. You may also export local certifi-
cates in PEM format or as PKCS #12.
The tab CA shows all existing Certification Authorities.
The tab Certs shows all available certificates.
The tab Revoked shows all invalid CAs and certificates.
fig. 176 list of available CAs