Chapter 14 Certificates
NWA3000-N Series User’s Guide
173
• Key distribution is simple and very secure since you can freely distribute public
keys and you never need to transmit private keys.
Self-signed Certificates
You can have the NWA3000-N series AP act as a certification authority and sign its
own certificates.
Factory Default Certificate
The NWA3000-N series AP generates its own unique self-signed certificate when
you first turn it on. This certificate is referred to in the GUI as the factory default
certificate.
Certificate File Formats
Any certificate that you want to import has to be in one of these file formats:
• Binary X.509: This is an ITU-T recommendation that defines the formats for
X.509 certificates.
• PEM (Base-64) encoded X.509: This Privacy Enhanced Mail format uses
lowercase letters, uppercase letters and numerals to convert a binary X.509
certificate into a printable form.
• Binary PKCS#7: This is a standard that defines the general syntax for data
(including digital signatures) that may be encrypted. A PKCS #7 file is used to
transfer a public key certificate. The private key is not included. The NWA3000-
N series AP currently allows the importation of a PKS#7 file that contains a
single certificate.
• PEM (Base-64) encoded PKCS#7: This Privacy Enhanced Mail (PEM) format uses
lowercase letters, uppercase letters and numerals to convert a binary PKCS#7
certificate into a printable form.
• Binary PKCS#12: This is a format for transferring public key and private key
certificates.The private key in a PKCS #12 file is within a password-encrypted
envelope. The file’s password is not connected to your certificate’s public or
private passwords. Exporting a PKCS #12 file creates this and you must provide
it to decrypt the contents when you import the file into the NWA3000-N series
AP.
Note: Be careful not to convert a binary file to text during the transfer process. It is
easy for this to occur since many programs use text files by default.
14.1.3 Verifying a Certificate
Before you import a trusted certificate into the NWA3000-N series AP, you should
verify that you have the correct certificate. You can do this using the certificate’s
fingerprint. A certificate’s fingerprint is a message digest calculated using the
Summary of Contents for NWA-3160
Page 2: ......
Page 14: ...Table of Contents NWA3000 N Series User s Guide 14 ...
Page 15: ...15 PART I User s Guide ...
Page 16: ...16 ...
Page 30: ...Chapter 1 Introduction NWA3000 N Series User s Guide 30 ...
Page 48: ...Chapter 2 The Web Configurator NWA3000 N Series User s Guide 48 ...
Page 54: ...Chapter 3 Configuration Basics NWA3000 N Series User s Guide 54 ...
Page 72: ...Chapter 4 Tutorials NWA3000 N Series User s Guide 72 ...
Page 73: ...73 PART II Technical Reference ...
Page 74: ...74 ...
Page 82: ...Chapter 5 Dashboard NWA3000 N Series User s Guide 82 ...
Page 146: ...Chapter 11 User NWA3000 N Series User s Guide 146 ...
Page 164: ...Chapter 12 AP Profile NWA3000 N Series User s Guide 164 ...
Page 170: ...Chapter 13 MON Profile NWA3000 N Series User s Guide 170 ...
Page 192: ...Chapter 14 Certificates NWA3000 N Series User s Guide 192 ...
Page 226: ...Chapter 15 System NWA3000 N Series User s Guide 226 ...
Page 252: ...Chapter 17 File Manager NWA3000 N Series User s Guide 252 ...
Page 262: ...Chapter 18 Diagnostics NWA3000 N Series User s Guide 262 ...
Page 264: ...Chapter 19 Reboot NWA3000 N Series User s Guide 264 ...
Page 266: ...Chapter 20 Shutdown NWA3000 N Series User s Guide 266 ...
Page 284: ...Chapter 22 Product Specifications NWA3000 N Series User s Guide 284 ...
Page 318: ...Appendix B Importing Certificates NWA3000 N Series User s Guide 318 ...
Page 372: ...Appendix D Open Software Announcements NWA3000 N Series User s Guide 372 ...
Page 378: ...Appendix E Legal Information NWA3000 N Series User s Guide 378 ...