This section allows you to secure your web access with a new TLS certificate.
Installed Certificate
The first section shows the installed certificates. You can use 2 different certificates on ESG for the web interface and the MTA.
Configure Certificates
In this section you can configure one or more TLS certificates. From this tab, you have options to:
- create a new self-signed certificate using Let’s Encrypt authority
- generate a new certificate request to submit to your CA (CSR Certificate)
- upload your own
- upload your wildcard certificate (Standard PEM – Base64 format)
- create a certificate using Let's Encrypt
Self Signed Certificate / Certificate Request
To create a new Self Signed Certificate or CA Request for your appliance, please fill in the followings:
- Common Name The fully qualified name of your LibraCyber ESG
- Email Address A valid email address that will be shown on the certificate
- Country Code Your two-letter IANA country code
- Locality Name Your town or city (NO SPACES)
- Organization Name Your organization name (NO SPACES)
- Organization Unit A dot (period) is usually appropriate here (NO
- Key Size: The size of the encryption key
NOTE: If you selected to generate a Certificate Request, you must paste back your certificate file once generated with your CA.
Wildcard Certificate
It is possible to upload your wildcard TLS certificate. Please note that the certificate must be in Standard PEM - Base 64 format and both private key and certificate file are requested. The upload extensions allowed are:
- Certificate File (*.crt)
- Key File (*.key)
Let’s Encrypt certificate
The process is completely automated. Once filled in the required fields the certificate is issued and installed. NOTE: LibraCyber ESG web interface must be accessible from the internet (the port 80 must be open). Let’s Encrypt certificates expire every 3 months. One month before expiration ESG automatically renews the certificate. If the renewal fails for any reason (like a temporary networking issue), a new attempt is made one week later, and so on with a new renewal attempt every week. 20 days before the expiration you will get an email notification from Let’s Encrypt, a new reminder will be sent 10 days before expiration, and a final email notification as soon as the certificate expires.