Solved

OpenSSL | PKI | Watchguard

Posted on 2010-09-16
4
1,158 Views
Last Modified: 2012-05-10
I need to generate a private key using OpenSSL for my watchguard firebox, but what i don't understand is how does the box know what the private key is?  its being genereted by an external program (openSSL).

Can someone explain to me how you tell the device what the private key is?

my SSL 100 box wants a server certificate and a client certificate.  The older version of the box used to genereate the CSR for you and it was much more straight forward.

any help would be appreciated.
0
Comment
Question by:beaconlightboy
  • 3
4 Comments
 
LVL 31

Expert Comment

by:Paranormastic
ID: 33702615
For the SSL 100 using version 3.1 (which appears to be the current version) here are the instructions:
http://www.watchguard.com/help/docs/ssl/3/en-US/v3_1_WG_SSL_WebUI_UserGuide.pdf

See printed page 300, Adobe page 312 - it seems to walk you through the whole process.  Let me know what step you are getting hung up on if you are having issues with what they are presenting.
0
 
LVL 31

Expert Comment

by:Paranormastic
ID: 33702634
The server cert is for hosting the SSL session.  If you need to connect to another box where client certificate authentication is being used for some purpose then you would create a client cert as directed.
0
 
LVL 3

Author Comment

by:beaconlightboy
ID: 33703523
well, i read this, it is identical to the help file.  Where i'm getting lost is how the box knows what the private key is.  if you generate a private key, then submit it, you don't get the private key back in the request.  So when you add the public key to the box, how does it know what it's private key is?
0
 
LVL 31

Accepted Solution

by:
Paranormastic earned 500 total points
ID: 33729339
The private key is generated as the first step in the OpenSSL procedure, just before creating the CSR file:
openssl genrsa -out wgnet.key 1024

wgnet.key is the private key (you can call this whatever you want)

Then you create the CSR and get your cert issued from the CA.

Sounds like you need to convert the private key to PKCS #8 format - this is not very commonly done but there are a few products that require it:
openssl pkcs8 -topk8 -in wgnet.key -out wgnet.pk8

Then you import the CA certs one at a time, from the root down, then you go to a screen where you import the issued cert and the PKCS #8 formatted private key in the same step - see printed page 304 / adobe page 316 for a screenshot under #3.

Hopefully this answers your question...
0

Featured Post

How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

Join & Write a Comment

Hi All,  Recently I have installed and configured a Sonicwall NS220 in the network as a firewall and Internet access gateway. All was working fine until users started reporting that they cannot use the Cisco VPN client to connect to the customer'…
SSL stands for “Secure Sockets Layer” and an SSL certificate is a critical component to keeping your website safe, secured, and compliant. Any ecommerce website must have an SSL certificate to ensure the safe handling of sensitive information like…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now