Please enable JavaScript to view this site.

For the productive operation of the SEPPmail Secure E-Mail Gateway including GINA technology, we urgently recommend using a trusted SSL machine or wildcard certificate for the SSL-secured access to the GINA webmail system.

 

To integrate a purchased trusted SSL certificate, navigate to the item SSL and click the Import existing certificate... button.

 

In the menu appearing thereafter, in Upload EXISTING CERTIFICATE, the certificate can be integrated in two ways – depending on the current certificate format (pem or PKCS#12 i.e. p12 or pfx).

 

Parameters

Description

PKCS12 file

The internet browser button "Select file" is used to select the PKCS#12 file (with the extension .p12 or .pfx).

PKCS12 password

Since a PKCS#12 file contains the private key, this file is password-protected. The password must be entered in this input field before importing the PKCS#12 file selected above.

PEM file

The internet browser button "Select file" is used to select the PEM file (with the extension .pem).

 

empty

anchor link Note:

When importing a PEM file, make sure that the private key contained in it is not encrypted!

PEM text

This field is used to insert the private key, the public key and, if applicable, the intermediate certificates as text. If the private key is password-protected, this must first be removed. The entry should therefore look similar to this:

-----BEGIN PRIVATE KEY-----

# Private key

-----END PRIVATE KEY-----

-----BEGIN CERTIFICATE---

# Public key

-----END CERTIFICATE-----

-----BEGIN CERTIFICATE---

# A possibly required intermediate certificate

-----END CERTIFICATE-----

-----BEGIN CERTIFICATE---

# Possibly additional intermediate certificates required

-----END CERTIFICATE-----

 

empty

anchor link Note:

No matter which method is used to import the SSL key pairs, it is important to ensure that all necessary intermediate certificates for a complete certificate chain are included. An incomplete certificate chain always leads to problems when the remote peer checks the certificates if it does not already have the missing intermediate certificates. Internet tools – such as CheckTLS – then show that the certificate chain is not complete and thus report an unknown certificate.

The root certificate of the root certification authority must not be added since the remote peer must trust it anyway! If it is added, some test tools report errors, such as "Chain issues - Contains anchor".

Not every PKCS12 or PEM file contains the complete certificate chain. In this case, the required intermediate certificates may have to be obtained elsewhere and embedded in the certificate to be imported.

 

Clicking the Upload key and certificate button uploads the SSL certificate to the appliance.

 

Detailed information can be found under REQUEST OR CREATE NEW CERTIFICATE (AUTHORITY).

  

Keyboard Navigation

F7 for caret browsing
Hold ALT and press letter

This Info: ALT+q
Topic Header: ALT+t
Topic Body: ALT+b
Contents: ALT+c
Search: ALT+s
Exit Menu/Up: ESC