The CA-signed certificate chain for the Manager and the Sensor is considered valid if the following conditions are met:
The CSR should not be modified after exporting from the Manager. This will cause the certificate validation in the Manager to fail.
The certificate must be X.509v3 version.
The CA-signed certificate chain should comply with the following requirements:
Should be issued from a trusted Certificate Authority
Should be in .pem format
Must contain valid serial numbers and valid issuer domain name
The number of intermediate CA-certificates in the certificate chain should be between 0 and 4.
The certificate chain should be in correct order. The chain should begin with the identity certificate (also known as leaf certificate) followed by intermediate CA-certificate 1, intermediate CA-certificate 2, ... intermediate CA-certificate N and end with the root CA-certificate.
The identity certificate must be signed by the intermediate CA. The intermediate certificate must be signed by the root CA.
The Basic Constraint CA flag must be set to True in case of root and intermediate certificates. For identity certificate, the flag must be set to False.
The certificate must comply with the following parameters:
ExtendedKeyUsage: TLS WebServerAuthentication and TLS WebClientAuthentication
KeyUSage: Must not be set to Critical.
Ensure that the validity period for the certificate specifies a valid date range.
OCSP requests and responses use
CertID.issuerNameHashandCertID.issuerKeyHashparameters to validate the revocation status of CA certificates.Note
In a Common Criteria (CC) evaluated configuration, revocation using OCSP is not claimed for Sensor - Manager channel.
Currently, the Manager supports SHA-1 hashing algorithm for the two parameters which needs to be managed in OCSP server configuration.