The following sections describe how you would set up the Screen and the Windows 2000 system to interoperate.
Generate a Certificate Signing Request
From the Common Objects panel, select Generate IKE Certificate
When the IKE Certificate dialog appears, click the Generate CA Request button; see Figure 9-4
Fill in the required fields.
Type in a Distinguished Name and make sure that the Encryption Type and Key Size match the related parameters used by the Windows 2000 system for its own certificate.
Click the Generate button.
SunScreen generates a Certificate Signing Request (CSR) and also creates and stores a private key. The following figure shows the CSR.
You can copy the text or save into a file for use in your signing request.
Present the CSR to the CA.
Have the certificate signed and acquire the new certificate.
Import the CA signed certificate into the Screen
From the common Objects panel, choose Import IKE Certificate. The Import IKE Certificate screen appears
Specify a name and description.
Choose an import method
Click the appropriate button and then either specify a file to import or paste the signed certificate into the text area.
Click the Install Certificate button.
Add the IKE Root CA Certificate to the Screen.
You accomplish this task by adding the Root CA certificate to the IKE root CA Certificates GROUP object.
Acquire the Root CA certificate and import it into the Screen's certificate store.
After you finish the import, in the Common Objects panel, search for the IKE root CA certificates object.
When you find the object, select it and click the edit button. The Certificates object dialog appears. See Figure 9-6.
Select the Root CA certificate you want and add it to the Include List.
Click OK to finish the task.
Edit the Root CA certificate object.
A requirement of Windows 2000 for IKE interoperability is that you must specify the Root CA certificate by its ISSUER Distinguished Name.