Managing Trusted CAs
R81.10.X Quantum Spark 1500, 1600, 1800, 1900, 2000 Appliances Locally Managed Administration Guide|358
To edit a trusted CA's configuration:
1. Select the CA from the list.
2. Click Edit.
3. Select the necessary options regarding CRL (Certificate Revocation List):
n
Retrieve CRL from HTTP Server(s) - HTTP can be used to access the CA for CRL
retrieval. When cleared, this appliance does not attempt to validate the remote
site's certificate's CRL.
n
Cache CRL on the Security Gateway - Select how often is a new updated CRL is
retrieved.
l
Fetch new CRL when expires - Upon expiration of the CRL.
l
Fetch new CRL every X hours - Regardless of CRL expiration.
4. Click Details to see full CA details.
5. Click Apply
To delete a trusted CA:
1. Select the trusted CA from the list and click Delete.
2. Click OK in the confirmation message.
To export the Internal CA (or other previously imported CAs):
1. Select the Internal CA in the table.
2. Click Export.
The Internal CA's identifier file is downloaded through your browser and is available to be
imported to the remote site's trusted CA list.
3. You can also export other trusted CAs you've added to the list if necessary by selecting
them and clicking Export.