You must import a certificate to make it active. If you plan to use a certificate for VPN authentication on an existing tunnel, you must also change the VPN tunnel configuration to use the new certificate. No additional configuration is necessary for Trusted CA certificates.
Local certificates must include an unencrypted private key in the certificate file to operate correctly.
Importing a Certificate
- From the System Status page on the Firebox X Edge, select Administration > Certificates.
- Adjacent to the type of certificate you want to add, click Import.
- If your certificate is in the PEM format, copy and paste the certificate contents into the text box, or select the second radio button and click Browse to select the certificate file.
- If your certificate is in the PKCS12 format, select the last radio button and click Browse to select the certificate file. This option is only available for Local Firebox X Edge certificates.
- Click Import. You can repeat steps 2-5 to add more certificates.
You can examine a certificate you have already imported to see its properties, including its expiration date, issuing authority, or other information.
- From the System Status page on the Firebox X Edge, select Administration > Certificates.
- Select the certificate you want to examine, then click the adjacent Detail button.