11.3.7. Trusted CAs

This menu item is for managing certificate authorities. The upper section of the panel displays the list of available CAs, both internal and external. Apart from creating the default internal CAs, the certificates of a number of trustworthy external ones (for example, VeriSign, NetLock) is imported as well. The following information is displayed on each:

  • Common name of the CA

  • Parts: Components of the certificate entity available for the CA.

    • c: certificate. Usually this is the only part available for external CAs.

    • k: private key of the certificate.

    • r: CSR.

    • l: CRL of the CA.

    An internal CA is fully functional if all of its parts are available (CRL is optional) .

  • Trusted groups: Name(s) of the trusted groups that the CA is member of.

  • Not before/not after: Validity of the CAs certificate.

  • CRL expiry: Date until the CRL of the given CA is valid. If this field is empty, no CRL has been released by the CA so far.

Trusted CAs

Figure 11.9. Trusted CAs