Please enable JavaScript to view this site.

This submenu is called up from X.509 Certificates.

 

Sections on this page:

Issued to

Issued by

Validity

Fingerprint

Valid e-mail addresses

Key usage

Key info

Comment

 

 

LinkSection Issued to

 

This section displays information about the owner of the SSL certificate.

Depending on the certificate, not all parameters listed here must be given.

 

Parameters

Description

LinkName (CN)

This field contains the name of the applicant as it was transmitted to the CA with the application for the certificate.

This may sometimes include the email address in the following form

Email: john.doe@mycompany.tld

Generally, however, email addresses are no longer accepted as "CN".

LinkEmail address

Generally, the email address of the applicant is displayed.

This can also be a collective address.

LinkOrg. unit (OU)

Organisational unit, such as a department name, e.g. "Accounting"

LinkOrganisation (O)

Specifies the organisation for which the certificate was issued, for example

My Company Corporation

LinkLocality (L)

Location, for example a town like "Neuenhof" or also a partial building like plant2

LinkState (ST)

Federal state, canton, province or similar, for example

Paradigm State

LinkCountry (C)

Country, for example

com

for "commercial"

LinkSerial no.

Serial number of the certificate

LinkSubject Alternative Name

Displays the Email address as well as any applicable alternative names.

 

 

LinkSection Issued by

 

This section displays information about the issuer of the SSL certificate (root certificate).

Depending on the issuer, not all parameters listed here have to be given.

 

Parameters

Description

LinkName (CN)

Name of the issuing certification authority

LinkEmail address

Generally, this is an email address for support enquiries to the issuer

LinkOrg. unit (OU)

Specifies an organisational unit of the issuer

LinkOrganisation (O)

Specifies the issuing organisation

LinkLocality (L)

Indicates the location of the issuer

LinkState (ST)

Indicates a federal state, canton, province or similar where the issuer is located

LinkCountry (C)

Specifies the country where the issuer is located

LinkSerial no.

Serial number of the certificate

 

 

LinkSection Validity

 

Shows the validity of the certificate.

 

Parameters

Description

LinkIssued on

Issue date of the certificate

LinkExpires on

Expiration date of the certificate

 

 

LinkSection Fingerprint

 

The fingerprint is the checksum (also hash) and is used to verify a certificate. At this point, the hash algorithm (for example MD5 SHA1 or SHA256) with which the checksum was formed as well as the calculated value are displayed. If several fingerprints of different algorithms are available, each one is output in a separate line.

 

Parameters

Description

LinkSHA1

SHA1 fingerprint of the certificate

Example:

D8:CF:CC:47:84:92:A9:F0:7E:2A:15:E8:2E:4F:CA:26:5C:60:10:E9

LinkSHA256

SHA265 fingerprint of the certificate

Example:

83:06:F6:84:34:C2:E7:79:50:47:7B:EC:32:B7:22:13:FD:1F:9C:41:B4:B4:F9:C3:AB:85:12:AA:6B:1E:D2:BE

 

 

LinkSection Valid e-mail addresses

 

In this section you can specify alternative email addresses for which the keys are also to be available. Thus a certificate which is primarily issued for

Associated Email Address: john.doe@mycompany.tld

and therefore, as applicant, something like

E = john.doe@mycompany.tld

CN = John Doe

O = My Company Corporation

C = com

would be indicated, could also be used for the alternative email addresses j.doe@mycompany.tld and doe@mycompany.tld for encryption if these addresses were entered.

This could be helpful, for example, when changing the top-level domain of an email domain from .uk to .com.

After saving via Save addresses, an additional input field is displayed.

 

empty

LinkNote:

This setting only works with key material which was uploaded with 7.4.6 or higher

 

 

 

LinkSection Key usage

 

Displays the intended purpose of the certificate, taking only the purposes from the following table into account.

 

Parameters

Description

LinkS/MIME signing

digitalSignature/digital signature

LinkS/MIME encryption

keyEncipherment/key encryption

LinkCA certificate

keyCertSign/certificate signature

LinkAllow encryption

Indicates whether this certificate is used for encryption to the applicant (Issued to) and/or to the email address(es) entered under Valid e-mail addresses.

 

empty

LinkNote:

This option is generally active for certificates collected from signatures and imported by the administrator.

 

Administrators may use this option to exclude the respective certificate from the use for encryption.

 

However, GINA users are also able to exclude their certificates, no matter how they were integrated into the X.509 Certificates.

For this reason, you should refrain from a general (re-)activation of this option by an administrator.

 

Click on Save usage to save changes.

 

 

LinkSection Key Info

 

Displays advanced information about the certificate.

 

Parameters

Description

LinkSignature algorithm

Shows the signature algorithm of the certificate, for example

md5WithRSAEncryption

sha1WithRSAEncryption

sha256WithRSAEncryption

LinkKey type

Displays the crypto system with which the key has been generated.

Generally, this is RSA.

LinkKey size

Shows the key length.

Generally, only key lengths of 2048 bit and more are used.

LinkLast certificate check

Displays the point in time of the last certificate check (via CRL or OCSP).

With Check now... you can force an immediate check of the revocation information.

LinkLast successful certificate check

Displays the date of the last successful OCSP and/or CRL check.

LinkLast check result

Displays the result of the last certificate check.

LinkOCSP URI

Outputs the authority information access (abbreviated AIA) - i.e. the OCSP path.

This item is only visible if the extension authority information access is set in the certificate.

LinkCRL URI

Outputs the crlDistributionPoint (distribution point for revocation lists), i.e. the location under which the CRL is made available.

This item is only visible if the extension crlDistributionPoint is set in the certificate.

LinkPublic / private key

Specifies which keys are included, private, public/

 

 

LinkSection Comment

 

Here, you can enter a personal comment about the certificate, for example why the corresponding trust position was selected.

Click on Save comment to save this comment.

 

 

Clicking the Download certificate button allows you to save the certificate in CRT format.

With Delete certificate, the certificate is revoked by the SEPPmail Secure E-Mail Gateway and deleted by a second click, if applicable.

 

  

Keyboard Navigation

F7 for caret browsing
Hold ALT and press letter

This Info: ALT+q
Topic Header: ALT+t
Topic Body: ALT+b
Contents: ALT+c
Search: ALT+s
Exit Menu/Up: ESC