This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revision | Next revisionBoth sides next revision | ||
how_to:create_an_ssl_certificate [2010/02/03 10:23] – paul | how_to:create_an_ssl_certificate [2011/01/27 09:25] – paul | ||
---|---|---|---|
Line 1: | Line 1: | ||
======How to create an SSL Certificate====== | ======How to create an SSL Certificate====== | ||
+ | VPOP3 Enterprise supports SSL certificates for encrypted sessions. | ||
+ | |||
The basic mechanism to create an SSL certificate is that you have to generate a **CSR** (Certificate Signing Request) then send that to a **CA** (Certificate Authority) who will sign your certificate and give you the certificate back. | The basic mechanism to create an SSL certificate is that you have to generate a **CSR** (Certificate Signing Request) then send that to a **CA** (Certificate Authority) who will sign your certificate and give you the certificate back. | ||
- | When you generate the CSR, you will also generate a **Private Key** file. This isn't sent anywhere, but is needed, so keep it safe. | + | When you generate the CSR, you will also generate a **Private Key** file. This isn't sent anywhere, but is needed, so keep it safe. For VPOP3' |
VPOP3 requires certificates & private keys to be in .PEM (Privacy Enhanced Mail) format which is a common format used by most people other than Microsoft. There are ways to convert .P12 .PFX and .CER files to PEM format, but those are outside the scope of this article. | VPOP3 requires certificates & private keys to be in .PEM (Privacy Enhanced Mail) format which is a common format used by most people other than Microsoft. There are ways to convert .P12 .PFX and .CER files to PEM format, but those are outside the scope of this article. | ||
Line 12: | Line 14: | ||
You can also set up as your own CA. The GenCert program above will let you do this, other programs are available to do this. This is free, but when you access a service using a certificate signed by your own CA, the email client or web browser may warn you that the certificate is not validated properly, and you will need to accept the warning. The data will still be encrypted just as with a £800 Verisign certificate, | You can also set up as your own CA. The GenCert program above will let you do this, other programs are available to do this. This is free, but when you access a service using a certificate signed by your own CA, the email client or web browser may warn you that the certificate is not validated properly, and you will need to accept the warning. The data will still be encrypted just as with a £800 Verisign certificate, | ||
- | We can obtain GeoTrust certificates for you for £49 (+VAT if applicable) per year. Please [[mailto: | + | Note that the ' |
+ | |||
+ | =====Obtaining a certificate===== | ||
+ | You can self-sign certificates or get them from a Certificate Authority. | ||
+ | |||
+ | We can obtain | ||
+ | |||
+ | Please note that if you get a certificate from another source there is a limited amount we can do if there is a problem since you may have requested the wrong type of certificate or have the wrong settings. If we supply a certificate it will work with VPOP3 Enterprise, if someone else supplies it we cannot guarantee that. | ||
+ | |||
+ | =====Intermediate Certificates===== | ||
+ | A lot of certificates nowadays need to have an ' | ||
+ | |||
+ | < | ||
+ | -----BEGIN CERTIFICATE----- | ||
+ | <site certificate> | ||
+ | -----END CERTIFICATE----- | ||
+ | -----BEGIN CERTIFICATE----- | ||
+ | < | ||
+ | -----END CERTIFICATE----- | ||
+ | </ | ||
+ | If the issuing certificate authority requires an intermediate certificate you will have to get that certificate' | ||
+ |