Certificate Enrollment Object key options
Cloud-Delivered Firewall Management Center navigation path
, and click Add Certificate Enrollment to open the Add Certificate Enrollment dialog box, and select the Key tab.
Fields
-
Key Type: Choose RSA, ECDSA, EdDSA.
Note-
EdDSA is not supported for EST enrollment type.
-
EdDSA is supported only in Site-to-Site VPN topologies.
-
EdDSA is not supported as an identity certificate for Remote Access VPN.
-
-
Key Name: Specifies the name of the key pair. If the key pair already exists, this field refers to the existing name. If not, it defines the name for a new key pair to be generated during enrollment. If no name is specified, the fully qualified domain name (FQDN) key pair is used instead.
-
Key Size: When generating a new key pair, defines the desired key size (modulus) in bits. The recommended size is 2048 bits. Larger modulus sizes offer more security but require more time (a minute or more when larger than 512 bits) to generate and process.
Important-
On Cloud-Delivered Firewall Management Center and Firewall Threat Defense Versions 7.0 and higher, you cannot enroll certificates with RSA key sizes smaller than 2048 bits and keys using SHA-1 with the RSA Encryption algorithm.
-
You can use the PKI Enrollment of Certificates with Weak-Crypto to allow certificates with SHA-1 and smaller key size.
-
You cannot generate RSA keys with sizes smaller than 2048 bits for Firewall Threat Defense 7.0, even when you enable the weak-crypto option.
-
-
Advanced Settings: Select Ignore IPsec Key Usage if you do not want to validate values in the key usage and extended key usage extensions of IPsec remote client certificates. You can suppress key usage checking on IPsec client certificates. By default, this option is not enabled.
NoteFor site-to-site VPN connection, if you use a Windows Certificate Authority (CA), the default Application Policies extension is IP security IKE intermediate. If you are using this default setting, you must select the Ignore IPsec Key Usage option for the object you select. Otherwise, the endpoints cannot complete the site-to-site VPN connection.