3.5.5
Certificates
Certificate types
The device uses different certificates to authenticate the various nodes.
Certificate
Is used in...
CA certificate
The CA certificate is a certificate issued by a Certificate Authority from which
the server, device and partner certificates are derived. To allow a certificate to
be derived, the CA certificate has a private key signed by the certificate au‐
thority.
The key exchange between the device and the VPN gateway of the partner
takes place automatically when establishing the connection. No manual ex‐
change of key files is necessary.
Server certificate
Server certificates are required to establish secure communication (e.g.
HTTPS, VPN...) between the device and another network participant. The
server certificate is an encrypted SSL certificate. The server certificate is
derived from the oldest valid CA, even if this is "out of service". The crucial
thing is the validity date of the CA.
SINEMA RC
Device certificate Certificates with the private key (key file) with which the device identifies itself. IPsec VPN (Page 286)
Partner certificate Certificates with which the VPN gateway of the partner identifies itself with the
device.
File types
File type
Description
*.crt
File that contains the certificate.
*.p12
In the PKCS12 certificate file, the private key is stored with the corresponding certif‐
icate and is password protected.
The CA creates a certificate file (PKCS12) for both ends of a VPN connection with the
file extension ".p12". This certificate file contains the public and private key of the local
station, the signed certificate of the CA and the public key of the CA.
*.pem
Certificate and key as Base64-coded ASCII text.
3.5.6
VPN
The device supports the following VPN systems
● IPsec VPN
● OpenVPN
3.5.6.1
IPsec VPN
You configure the IPsec connections in "Security" > " IPsec VPN (Page 281)".
With IPsec VPN, the frames are transferred in tunnel mode. To allow the device to establish a
VPN tunnel, the remote network must have a VPN gateway as the partner.
Technical basics
3.5 Security functions
SCALANCE S615 Web Based Management
Configuration Manual, 11/2019, C79000-G8976-C388-08
49