Hi experts,
My CLUSTER security gateway (R80.10) is using https inspection to control internet access. It is using certificate with SHA1. Now I need to upgrade SHA1 to SHA256.
I think I will follow sk115894 to generate new cert, but I still have some questions , please help clear, thank in advance:
>> I have a cluster, so where to generate cert (gateway 1 or 2 or on SMC) ?
>> After generating new cert, I will import cert into SMC as sk115894 guide. But about file server.key, its default location is /home/admin of firewall (where it was born) , so Do I need to move it to some required location?
>> If this new cert gets problem after activating on SMC (as sk115894 guide) , could I rollback to old cert like this below ?
Thank you!!!