
VE Quick Start Guide and Installation Guide 19
Import an Existing Certificate or Enroll a New Server Certificate
Certificates must be in place before you can activate users against DDP Enterprise Server - VE.
You can import an existing certificate or
create a certificate request through
the
DDP Enterprise Server - VE.
It is a best practice to restart the services any time a settings change is made.
Import an Existing Server Certificate
1
Export the existing certificate and its full chain of trust from its keystore.
NOTE: Keep the export password because you will enter it when you import the certificate into DDP Enterprise Server - VE.
2
Store the certificate to the FTP Server of the
DDP Enterprise Server - VE.
3
From the
DDP Enterprise Server - VE
Advanced Configuration
menu, select
Server Certificates
.
4
Select
Import Existing Certificate
.
5
Select a certificate file to be installed on DDP Enterprise Server - VE.
6
When prompted, enter the certificate export password and select
OK
.
7
When the import is complete, select
OK
.
Enroll a New Server Certificate
1
From the
Advanced Configuration
menu, select
Server Certificates
.
2
Select
New Server Certificate
.
3
Select
Create Certificate Request.
4
Complete the fields in the
Generate Certificate Request
screen:
— Two-letter country code.
—
State or province
: Enter the unabbreviated state or province name (example, Texas).
—
Locality or city.
Enter the appropriate value (example, Dallas).
—
Organization
: Enter the appropriate value (example, Dell).
—
Organizational unit
: Enter the appropriate value (example, Security).
—
Common name:
Enter the fully qualified domain name of the server where DDP Enterprise Server - VE is installed.
This fully qualified name includes the hostname and the domain name (example, server.domain.com).
—
Email ID:
Enter the email address to which your CSR will be sent.
5
Follow your organizational process for acquiring an SSL server certificate from a Certificate Authority. Send the contents
of the CSR file for signing.
6
When you receive the signed certificate, export the certificate as a .p7b file, and download the full chain of trust in .der
format.
7
Make backup copies of the certificate and chain of trust.
8
Upload the certificate file and its full chain of trust to the FTP Server of the DDP Enterprise Server - VE.
9 From the
Advanced Configuration
menu, select
Server Certificates
.
10
Select
New Server Certificate
.
11
Select
Complete Certificate Enrollment
.
12
Select the certificate file to be installed on DDP Enterprise Server - VE.
13
Enter the Certificate Password set when the Certificate Request was created.
To enable trust validation on Windows-based DDP|E encryption clients, see
Enable Manager Trust Chain Check
.
Comentarios a estos manuales