15.2 Creating Certificates Using the Appliance CA

Use the instructions in this section if you plan to configure browsers to access the appliance's caching services. Browsers need to import the appliance's CA in order to accept its certificates as legitimate.

If this is not done, users get certificate confirmation messages that might confuse them.

To create an appliance CA certificate:

  1. In the browser-based management tool, click Home > Certificate Maintenance > Create.

  2. Type an appropriate name for the certificate as explained in Section 15.1, Naming Certificates.

  3. Type an appropriate subject name as explained in Section 15.1, Naming Certificates.

  4. Click the Signature Algorithm drop-down list, then select the algorithm you want to use (SHA-1 or MD-5).

  5. Click the RSA Key Size drop-down list, then select the RSA key size that you want to use.

    You cannot select a key size larger than the maximum key size on the appliance.

  6. Check Use Local Certificate Authority.

  7. Click the Validity Period drop-down list, then select the length of time that you want the certificate to be valid.

  8. Click OK.

  9. Look at the Action and Status fields.

    The Action field should have red arrows on the left and the word Create displayed on a green background. The Status should be Building.

    The red arrows and green background indicate that you need to click Apply.

  10. Click Apply.

    If any errors occur during the certificate creation process, they are displayed in the Error field on a red background.

  11. If an error occurs, click Modify

  12. In the Modify Certificate dialog box, make the changes necessary to resolve the errors, then click OK.

  13. Click Apply and repeat the modification process until the Status field displays the word Active.