Generate certificate signing request
The device allows you to generate a certificate signing request (CSR) which can be sent to a CA.
- Go to Certificates and click Add.
- Set Action to Generate certificate signing request (CSR).
-
Certificate details
- Enter the Certificate name.
-
Specify the certificate’s validity period.
Default: 1 day
-
Select the number of bits used to construct the key from the list.
Note Larger keys offer greater security, but take longer to encrypt and decrypt data.
Default: 2048
- Select to encrypt the key. Enter a passphrase or the pre-shared key and re-confirm
-
Specify the certificate ID for one of the following options:
- DNS
- IP address (IPv4/IPv6 address)
- DER ASN1 DN (X.509)
-
Identification attributes
- Select the country in which the device is deployed.
- Enter the state within the country.
- Enter the locality in which the certificate is to be used.
- Enter the name of the certificate owner (example: Sophos Group).
- Enter the name of the department to which the certificate is to be assigned (example: marketing).
- Enter the common name or FQDN (example: marketing.sophos.com).
- Enter the contact person’s email address.
-
Click Save.
Once the certificate is created, you need to download and send this certificate to the remote peer with whom the connection is to be established.