Dell Security Management Server and Virtual Server SSL and TLS Certificate Minimum Requirements

Oversigt: This document is to assist customers with the minimum requirements to request SSL/TLS certificates for use by the Dell Data Security server.

Denne artikel gælder for Denne artikel gælder ikke for Denne artikel er ikke knyttet til et bestemt produkt. Det er ikke alle produktversioner, der er identificeret i denne artikel.

Instruktioner

Affected Products:

  • Dell Security Management Server
  • Dell Data Protection | Enterprise Edition
  • Dell Security Management Server Virtual
  • Dell Data Protection | Virtual Edition

Dell Data Security includes the convenience of creating and using a self-signed certificate for secure communication between the server and clients. However, as with all self-signed certificates, there are security considerations when choosing what type of certificate to use.

To enhance security, it is recommended to request an SSL/TLS certificate using an internal or well-known third-party Certificate Authority (CA).

The recommendations and minimum requirements for an SSL/TLS certificate for use by the Dell Data Security server are:

  • Certificate Signing Requests (CSRs) must include a Common Name (CN).
  • Certificate Signing Requests (CSRs) must include a Subject Alternative Name (SAN). This must be a DNS entry that matches the Common Name.
  • Include other common fields such as Country (C), State (ST), and Organization (O).
  • Use at least SHA-256 (SHA-2 signing should be used on the request. This may be unnecessary if the CA overrides the algorithm that is specified in the request. The resulting certificate must be SHA-2 signed. MD5 and SHA-1 are deprecated and no longer supported).
  • Private keys must be at least RSA 2048-bit.
  • Private keys must be exportable.
  • Version 9.3 and earlier, each certificate in the chain must have an AuthorityKeyIdentifier which matches the signing certificate’s SubjectKeyIdentifier.
    Note: If any DNS names are specified in the Subject Alternative Name (SAN) extension that is in the request, then the CN field is not matched when validating the certificate as specified in section 6.4.4 of RFC 6125.

Unsupported configurations:


To contact support, reference Dell Data Security International Support Phone Numbers.
Go to TechDirect to generate a technical support request online.
For additional insights and resources, join the Dell Security Community Forum.

Berørte produkter

Dell Encryption
Artikelegenskaber
Artikelnummer: 000124821
Artikeltype: How To
Senest ændret: 08 aug. 2024
Version:  11
Find svar på dine spørgsmål fra andre Dell-brugere
Supportservices
Kontrollér, om din enhed er dækket af supportservices.