cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1361
Views
0
Helpful
2
Replies

Generate a PEM certificate and use it in several Ironport

issael morales
Level 1
Level 1

You can generate a certificate in PEM ironports and the same use in other Ironports

1 Accepted Solution

Accepted Solutions

Andreas Mueller
Level 4
Level 4

Hello Issael,

that is possible and quiet often used, i.e with a wildcard certificate where  CN=*.example.com supporting any given interface name on each appliance, mail1.example.com, mail2.example.com, ....etc. If that is too expensive, and you are using only one IP  for outbound traffic (i.e. behind a NAT), then use a normal cerificate and assign the same interface name to all appliances where traffic goes out. You could also use the subjectAltName in the certificate to specify the other appliances, but that is quiet complex and needs a specific look at the individual network setup.

Hope that helps,

Andreas

View solution in original post

2 Replies 2

Andreas Mueller
Level 4
Level 4

Hello Issael,

that is possible and quiet often used, i.e with a wildcard certificate where  CN=*.example.com supporting any given interface name on each appliance, mail1.example.com, mail2.example.com, ....etc. If that is too expensive, and you are using only one IP  for outbound traffic (i.e. behind a NAT), then use a normal cerificate and assign the same interface name to all appliances where traffic goes out. You could also use the subjectAltName in the certificate to specify the other appliances, but that is quiet complex and needs a specific look at the individual network setup.

Hope that helps,

Andreas

Hello Andreas

thank you very much for your feedback.

regards