6.1.1 Apply a Trusted Signed Certificate for VPN Portal

Information

Apply a signed certificate from a trusted Certificate Authority (CA) to the SSL VPN portal to allow users to connect securely with confidence.

Having an unsigned or self signed certificate leaves connections open to man-in-the-middle attacks and could allow users to connect to untrusted servers.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Import a signed certificate from a trusted CA through the GUI:

1. Go to System > Certificates > Import.
2. Then assign the certificate to the SSL VPN portal by going to VPN > SSL-VPN Settings and selecting the proper certificate in the dropdown for "Server Certificate".

See Also

https://workbench.cisecurity.org/benchmarks/15284