9-26
Device Manager Guide, Cisco ACE 4700 Series Application Control Engine Appliance
OL-26645-02
Chapter 9 Configuring SSL
Configuring SSL CSR Parameters
Related Topics
• Configuring SSL, page 9-1
• Importing SSL Certificates, page 9-8
• Importing SSL Key Pairs, page 9-12
• Generating SSL Key Pairs, page 9-15
• Configuring SSL Parameter Maps, page 9-19
• Configuring SSL CSR Parameters, page 9-26
• Configuring SSL Proxy Service, page 9-28
Configuring SSL CSR Parameters
A certificate signing request (CSR) is a message you send to a certificate authority such as VeriSign and
Thawte to apply for a digital identity certificate. The CSR contains information that identifies the SSL
site, such as location and a serial number, and a public key that you choose. A corresponding private key
is not included in the CSR, but is used to digitally sign the request. The CSR may be accompanied by
other credentials or proofs of identity required by the certificate authority, and the certificate authority
may contact the applicant for more information.
If the request is successful, the certificate authority returns a digitally signed (with the private key of the
certificate authority) identity certificate.
CSR parameters define the distinguished name attributes the ACE appliance applies to the CSR during
the CSR-generating process. These attributes provide the certificate authority with the information it
needs to authenticate your site. Defining a CSR parameter set lets you to generate multiple CSRs with
the same distinguished name attributes.
Each context on an ACE appliance can contain up to eight CSR parameter sets.
Use this procedure to define the distinguished name attributes for SSL CSRs.
Procedure
Step 1 Choose Config > Virtual Contexts > context > SSL > CSR Parameters. The CSR Parameters table
appears.
Step 2 Click Add to add new set of CSR attributes, or select an existing entry to modify, and then click Edit.
The CSR Parameters configuration screen appears.
Step 3 In the Name field, enter a unique name for this parameter set. Valid entries are alphanumeric strings with
a maximum of 64 characters.
Step 4 In the Country field, enter the name of the country where the SSL site resides. Valid entries are 2
alphabetic characters representing the country, such as US for the United States. The International
Organization for Standardization (ISO) maintains the complete list of valid country codes on its Web site
(www.iso.org).
Step 5 In the State field, enter the name of the state or province where the SSL site resides.
Step 6 In the Locality field, enter the name of the city where the SSL site resides.
Step 7 In the Common Name field, enter the name of the domain or host of the SSL site. Valid entries are
alphanumeric strings with a maximum of 64 characters. The ACE supports the following special
characters: , . / = + - ^ @ ! % ~ # $ * ( ).
Comments to this Manuals