PreviousNext

Nortel


Importing and obtaining digital certificates

The NVC supports retrieval of X.509v3 certificates from Microsoft Certificate storage through the Microsoft CryptoAPI (MS CAPI). Microsoft provides a Public Key Infrastructure (PKI) that adheres to the Public-Key Cryptography Standards (PKCS).

Microsoft Certificate storage provides the NVC full access to the Microsoft Certificate storage and management tools. The Microsoft Certificate storage and management tools use PKCS standards-based messages and protocols to manage key pair generation and storage.

You can create certificate requests with tools that a Certification Authority (CA) supports and are integrated with MS CAPI.

When importing a certificate into the MS CAPI store, you must also import the issuing CA certificate.

MS CAPI support on the NVC provides checking the revocation status of the server certificate. If you receive the message The Server's Certificate has been revoked, or could not be validated. Please check with your remote access administrator. The Connection has been terminated., then the server certificate is actually revoked or the Certificate Revocation List (CRL) distribution point is inaccessible, as defined in the CRL distribution point extension of the servers X.509 certificate.

Make sure that the CRL distribution point is accessible to the PC after the NVC tunnel connection is complete. The NVC must be able to reach the CRL distribution point. An example CRL distribution point, as defined from the issuing CA, is http://sf1.certificates.com/CertEnroll/SF1.crl.

For more information about certificate selections after they are in the MS CAPI, see  Creating an IPSec profile using Manage Profles and  Creating a SSL profile using Manage Profles.


Nortel
http://www.nortel.com
PreviousNext