Skip to main content

证书管理

 The dashboard includes a 仪表盘包含一个Certificates证书 section to import, view, and delete certificates. Clicking a certificate row opens the certificate editor. 部分,用于导入、查看和删除证书。点击证书行将打开证书编辑器。

Certificates list证书列表

Certificates are displayed in a sortable, paginated table. The list includes both client certificates and Certificate Authorities证书以可排序、分页的表格显示。列表包含客户端证书和证书颁发机构 (CA).

Filters筛选器

At the top of the page you can enable filters using the chip list. Some filters are mutually exclusive.在页眉处,您可以通过芯片列表启用筛选器。某些筛选器是互斥的。

  • All全部: show all certificates.:显示所有证书。
  • Client客户端: show client certificates only.:仅显示客户端证书。
  • Certificate Authority证书颁发机构 (CA): show:仅显示 CA certificates only.证书。
  • Search搜索: shows a text field (label:显示一个文本框(标签 Name or filename名称或文件名) to search by certificate name or imported filename.)用于按证书名称或导入的文件名进行搜索。
  • Without user无用户: show client certificates not associated with any user.:显示未与任何用户关联的客户端证书。

Table columns表格列

  • Name名称
  • Type类型
  • Expiration到期
  • User用户 (shown for client certificates)(用于客户端证书)
  • Imported filename导入的文件名
  • Import date导入日期

Actions操作

  • Open certificate打开证书: click a row to open the certificate editor.:点击某一行以打开证书编辑器。
  • Delete certificate删除证书: available only when the certificate is not associated with users/policies and is not used by devices. The action can also be disabled when the license is expired.:仅当证书与用户/策略未关联,且未被设备使用时可用。当许可证过期时,此操作也可能被禁用。
  • Multi-row selection多行选择: you can enable multi-row selection to delete multiple certificates at once. Only deletable certificates can be selected.:您可以启用多行选择功能一次性删除多个证书。仅可删除的证书可被选中。
  • Refresh刷新: reload the certificates list.:重新加载证书列表。

Import certificates导入证书

To import certificates, click要导入证书,请点击 Import certificate导入证书 and并选择一个或多个文件。 select one or more files. Supported formats are shown in the tooltip of the import button. 支持的格式显示在导入按钮的提示工具中。

客户端

Supported支持的格式:Base64 format: base-64 encoded编码的 PKCS#12 (.p12 / .pfx).

Client certificates identify a user or a device on the enterprise network. Client certificates can be associated with a specific user.客户端证书可用于标识企业网络中的用户或设备。客户端证书可以与特定用户关联。

Each client certificate can be optionally assigned to a specific user: this allows deploying the same每个客户端证书可以选择性地分配给特定的用户:这允许在许多设备上部署相同的 Wi‑Fi EAP configuration on many devices. You can do that in the policy's配置。您可以在策略的 network configuration网络配置 section, using the部分,使用 用户的 EAP credentials from users凭据 option.选项来执行此操作。

或者,您也可以从您也可以从“用户页面分配证书给用户。”页面为用户分配证书。

证书颁发机构 (CA)

Supported支持的格式:Base64 formats: base-64 encoded编码的 X.509 (.crt / .pem / .cer / .der).

CA certificates identify a Certificate Authority and indicate to the device that any certificates issued by the证书用于标识证书颁发机构,并指示设备信任由该 CA should be trusted. The dashboard validates that an imported颁发的任何证书。仪表盘验证导入的 X.509 certificate证书是否为 is a CA.CA。

Certificate editor证书编辑器

When you open a certificate, the editor shows its main fields and a read-only 当您打开证书时,编辑器会显示其主要字段以及一个只读的Certificate information证书信息 panel.面板。

Main fields主要字段

  • Name名称 (required)必填)
  • Id标识符 (read-only)只读)
  • Type类型 (read-only)只读)
  • Expiration到期 (read-only)只读)
  • Import date导入日期 (read-only)只读)
  • Imported filename导入的文件名 (read-only)只读)

User association用户关联 (client certificates)客户端证书)

For对于 Client客户端 certificates, the editor shows a证书,编辑器会显示一个 User用户 field. If a user is assigned, a menu allows you to字段。如果已为用户分配,则菜单允许您 Open user打开用户,更改用户,或 Change user解除用户关联, or Disassociate user. If no user is assigned, you can assign one using the user action button.。如果未为用户分配,可以使用用户操作按钮进行分配。

Delete certificate删除证书

The delete action is disabled when the certificate is currently associated with a user or used in policies. It can also be disabled when the license is expired.当证书当前与用户关联或在策略中使用时,删除操作将被禁用。当许可证过期时,删除操作也可能被禁用。