How do I generate a new SSL certificate from my SonicWall firewall?

Description

Scenario
A network admin is trying to install a certificate, so that the web management of the device can be accessed without any certificate error.

CAUTION: Will require a restart of the firewall.

 In order to request and import a certificate from a certificate authority that will work on your appliance you will need to create a certificate signing request on the appliance.

Resolution for SonicOS 7.X

This release includes significant user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.

  1. Login to the appliance and navigate to Device | Settings | Certificates and click New Signing Request.

    Image

  2. Fill out the Certificate Signing Request with information on the fully qualified domain name (FQDN) you will be using for the SSL.
    TIP: Wildcard for a domain would be *.yourdomain.com, Wildcard cost more but authenticate all subdomains on the domain.

    Image
     
  3. Download the CSR. You can edit this with a text editor. Notepad ++ is a good option because it keeps the format that works best for copying a CSR request over to a certificate authority.

    Image

    Image


  4. Request a SSL from your certificate authority providing this CSR text where they request.
    NOTE:When downloading the signed certificate from the certificate authority (such as GoDaddy or Thawte) select the server platform Apache SSL.

    Image



  5. Once you get the certificate back from the certificate authority upload the certificate to the pending request.

    Image

    Image

    Image

    Image

  6. Restart the appliance to verify the certificate is installed and validated.
    TIP: If the certificate shows "Validated No" use the following article to import the certificate chain to validate the SSL. Imported Certificates Not Validating

  7. After the certificate is imported and validated, you may require to use this certificate for SSL VPN connection or Firewall HTTPS management.  To configure that, click on the article here How to use the SSL certificate for WAN Management and SSLVPN


Resolution for SonicOS 6.5

This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.

  1. Login to the appliance and navigate to Manage | Appliance | Certificates and click New Signing Request.
    Image

  2. Fill out the Certificate Signing Request with information on the fully qualified domain name (FQDN) you will be using for the SSL.

    TIP: Wildcard for a domain would be *.yourdomain.com, Wildcard cost more but authenticate all subdomains on the domain.


    Image
  3. Download the CSR. You can edit this with a text editor. Notepad ++ is a good option because it keeps the format that works best for copying a CSR request over to a certificate authority.ImageImage
  4. Request a SSL from your certificate authority providing this CSR text where they request.
    NOTE: When downloading the signed certificate from the certificate authority (such as GoDaddy or Thawte) select the server platform Apache SSL.

    Image

  5. Once you get the certificate back from the certificate authority upload the certificate to the pending request.
    ImageImageImageImage
  6. Restart the appliance to verify the certificate is installed and validated.
    TIP: If the certificate shows "Validated No" use the following article to import the certificate chain to validate the SSL: Importing Certificate Authority Chain.
  7. After the certificate is imported and validated, you may require to use this certificate for SSL VPN connection or Firewall HTTPS management.  To configure that, click on the article here How to use the SSL certificate for WAN Management and SSLVPN


Related Articles

  • Using 31-Bit Prefixes on IPv4 Address Error: Index of the interface: Invalid IP Address
    Read More
  • How to block a website using CFS 4.0 CLI commands
    Read More
  • How to Configure Wire / Tap mode in SonicOS
    Read More
not finding your answers?
was this article helpful?