Configuring a CA Key for the Cluster
You will need to configure a CA key for the cluster if both the following apply:
gateway
You will need to configure a CA key for the cluster if both the following apply:
- The Gateway cluster will be communicating with the XML VPN Client.
- You expect to use the automatic client certificate provisioning feature in the XML VPN Client.
You do not need to configure a CA key for the cluster if either of the following applies:
- The Gateway cluster will not be communicating with the XML VPN Client.
- Client certificates have been manually imported into the XML VPN Client.
To configure a CA key for the cluster, use the
Manage Private Keys
task in the Policy Manager to create a new CA-capable key and then set it as the default. For more information, see "Managing Private Keys" and "Private Key Properties".