WatchGuard Technologies Water Heater SSL VPN Manuale Utente

Pagina di 195
Administration Guide
153
APPENDIX C
Installing Windows Certificates
The Firebox SSL VPN Gateway includes the Certificate Request Generator to automatically create a cer-
tificate request. After the file is returned from the Certificate Authority, it can be uploaded to the Firebox 
SSL VPN Gateway. When the file is uploaded, it is converted automatically to the correct format for use.
If you do not want to use the Certificate Request Generator to create the signed certificate, use Linux 
OpenSSL to administer any certificate tasks. If Linux is not available, Cygwin UNIX environment for Win-
dows is recommended, which includes an OpenSSL module. Instructions for downloading, installing, 
and using the Cygwin UNIX environment to generate a CSR are included in this section. 
If you are familiar with certificate manipulation, you can use other tools to create a PEM-formatted file. 
The certificate that you upload to the Firebox SSL VPN Gateway must have the following characteristics:
• It must be in PEM format and must include a private key
• The signed certificate and private key must be unencrypted
If Linux OpenSSL is not available, install the Cygwin UNIX environment for Windows. When you install 
Cygwin, you must choose the OpenSSL modules as described in the following steps.
To install Cygwin
1
Use a Web browser to navigate to http://www.cygwin.com and click Install Cygwin Now.
2
Follow the on-screen instructions to open the setup installer. 
3
In the Cygwin Setup dialog box, click Next.
4
Click Install from Internet and then click Next.
5
Accept the default root installation directory settings and then click Next.
6
Accept the default local package directory setting and then click Next.
7
In the Internet Connection screen, click Use IE5 Settings and then click Next.
8
In the list of Available Download Sites, click ftp://ftp.nas.nasa.gov and then click Next.
9
In the Select Packages screen, click the View button.
10
Scroll the packages list to locate in the Package column openssl: The OpenSSL runtime 
environment
 and openssl-devel: The OpenSSL development environment.
11
In the New column for those two entries, click Skip
The current version number of Cygwin appears.