Encrypting the connection to the SharpZ3 web portal using a certificate issued by a trusted certificate authority (CA) (Basic) - If the SharpZ3 unit uses a certificate issued by a CA, you must install the certificate on all machines that communicate with the unit. - Security Center 5.12

Security Center Hardening Guide 5.12

Product
Security Center
Content type
Guides > Administrator guides
Version
5.12
ft:locale
en-US
Last updated
2024-12-17

If the SharpZ3 unit uses a certificate issued by a CA, you must install the certificate on all machines that communicate with the unit.

What you should know

If you use a custom Certificate Authority or chain of trust, contact the AutoVu™ Support team for assistance.

Procedure

  1. On the machine where you want to register the certificate, sign in as an Administrator.
  2. Sign in to the Sharp Portal.
  3. From the Configuration menu, select the Security page.
  4. Click + Signing request.
  5. Enter the required information for the Certificate Signing request and click OK.
    NOTE:
    • The Country field requires a two-letter country code.
    • If you are also using the certificate to connect to the Archiver, the Sharp's common name defined in the certificate must be the Sharp unit's IP address, not the Sharp name.
    The message Operation succeeded is displayed and the signing request is added to the certificate list with not signed displayed for the Issuer.
  6. Click on the certificate to display the Certificate details.
  7. Click Copy to clipboard.
  8. Send the Certificate Signing request to a certificate authority.
    IMPORTANT: Do not delete the signing request if it has been used to request a certificate.
    You will receive an SSL certificate signed by the certificate authority.
  9. In the Certificate Details window, click Install signed certificate then browse to the root certificate location and click Open.
  10. Click Save.
    The system displays the message: Installed signed certificate... successful.
    NOTE: If you are not using a trusted CA such as VeriSign or DigiCertIf, you might receive the error The certificate chain is not trusted. Contact the AutoVu™ Support team for assistance.
  11. Refresh the browser (F5).
    The certificate is displayed in the Certificate list.
  12. Click the Active button for the certificate.
  13. Click Save and reboot and click OK to confirm the reboot.

Results

When the system comes back online, notice that the URL displays that you are in HTTPS mode. A lock icon () in the browser's address bar indicates that you are now logged on to the unit with a secure connection.