Adding authorities and certificates
The Add button has a drop-down list offering 6 options that will enable the creation of an authority
or a certificate, via a wizard.
Adding a root authority
A root authority or “root CA” is an entity that signs, sends and maintains certificates and CRLs
(Certificate Revocation Lists).
You will need to define the properties of the authority you wish to add:
Warning
This information cannot be modified after the creation of the authority is confirmed.
CN Enter a name that would allow you to identify your root authority, limited to a
maximum of 64 characters. This name may refer to an organization, a user, a server, a
host, etc.
Example
Stormshield Network
NOTE
This field has to be entered in order to continue the configuration.
Identifier Even though this field is not mandatory, you can indicate here a shortcut to your CN,
which will come in handy for your command lines.
Example
If you had selected a first name and last name for your CN, the ID may indicate just
the initials.
Select the parent CA (if necessary)
Selecting a parent authority involves first entering the authority’s attributes in the fields below.
Parent CA Even though a CA is made up of certificates, it can also involve sub-CAs that depend
on it.
A sub-CA can only be used after the identification of its “Parent authority” or CA.
Password for the
parent CA
Define a password if you wish to indicate that you are indeed in charge of the parent
CA.
Certificate authority attributes
During this step, you will need to enter general information regarding the authority that you wish
to implement. The information entered will be found in your CA’s certificate and in your users’
certificates.
NOTE
For sub-CAs, these data are already pre-entered. And unless you modify the configuration,
not all of this information can be modified later.
Organization (O) Name of your company (e.g.: COMPANY).
Organizational Unit
(OU)
"Branch" of your company (e.g.: INTERNAL).
Page 67/448 sns-en-user_configuration_manual-v3 - Copyright © Stormshield 2016
SNS - USER CONFIGURATION MANUAL V.3
CERTIFICATES AND PKI