Novell Netware 6.0 Support
During the online enrollment process you will be required to provide Entrust with a Certificate Signing Request (CSR).
This encrypted data is generated from your web server, and contains information about your company and web server.
! It is important to review this guideline, as Entrust will use this information to generate your certificate.! If you are renewing your certificate you MUST create a new key pair, you cannot use the existing key pair.
To generate your Key Pair and Certificate Signing Request (CSR) :
- Launch Console One
- Right click the container where your server resides
- Select New, then select Object
- From the 'New Object' window, select NDSPKI : Key Material
- Click OK
- From the 'Create Server Certificate (Key Material)' window, select the server you are requesting the certificate for
- Ensure the 'Custom' creation method radio button is selected
- Click Next
- Ensure the 'External certificate authority' radio button is selected
- Click Next
- Select a key size
- Ensure "Allow private key to be exported" is checked - setting this option will allow you to backup your key pair at a later stage
- Click Next
- Click the 'Edit' button located next to the 'Subject name' field
- Ensure that the subject name reflects the name of the URL you are requesting the certificate for. Entrust requires that the subject name contains at least 3 components :
- CN - common name
- O - Orgranization
- C - Country
- Click OK once you have properly configured the Subject Name
- Click Next
- In the window that appears, review the components you have specified to be used in the creation of your CSR, click Finish when done.
- Select the 'File in Base64 format' radio button, and specify a path and filename for your CSR.
- Click Save to complete generation of your CSR.
! Entrust does not supporting signing CSR's with a key length greater than 2048, please choose a length equal to or less than 2048.
! Do not use the following characters in any of the fields in the 'Create Server Certificate (Key Material)' window: > < ! @ # $ % ^ * ( ) ~ ? / \.! Do not specify the protocol (http://), any port numbers or pathnames in the Common Name (CN).
! Do not use wildcards such as * or ?.
You have successfully created your key pair and Certificate Signing Request.