Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
D_TK
Collaborator

Inbound ssl inspection - certificate question

Hello friends,

I would like to enable inbound ssl inspection to a few public facing appliances that are only accessed over ssl.  The issue seems to be that there is no "private key" for their certificates.  When it's time to renew their 3rd party trusted cert, all the appliances give us is CSR which we send to entrust and get back the server cert along with the root and intermediate certs.  Put those files together and install the cert on the appliance which has an A+ score from the public qualys ssl checker.

I've tried to create a .p12 file using this command:

cpopenssl pkcs12 -export -nokeys -in ServerCertificate.crt -out final.p12

For the -in file, i've tried just the server cert, and the full cert with root and intermediate added.  And when attempting to import to smartdashboard, i receive the "import certificate error".

I have a feeling that i'm fighting a losing battle here...is there anyway to do this?  Ver is r80,20, latest HFA.

 

thanks

 

 

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

R80.20 is End of Support, are you sure that's the version?

0 Kudos
D_TK
Collaborator

thanks for catching that.  typo.  Management is r81.20 and the gateway that would be enforcing the inbound inspection is r81.10.

 

thanks

 

0 Kudos
PhoneBoy
Admin
Admin

In order to do inbound HTTPS Inspection, we need an actual private key.
Is there a private key section in your .p12 that was generated?

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events