User Manual - Page 720

For 1474C009AA. Also, The document are for others Canon models: MF735CDW, MF733CDW, MF731CDW, MF634CDW, MF632CDW

Loading ...
Loading ...
Loading ...
IPSec supports communication to a unicast addr
ess (or a single device).
The machine cannot use both IPSec and DHCPv6 at the same time.
IPSec is unavailable in networks in which NAT or IP masquerade is implemented.
Registr
ation of Keys and Certicates
A certicate and key that can be generated by the machine conform to X.509v3. If you install a key or CA certicate
from a computer, make sure that they meet the following requirements:
Format
Ke
y: PKCS#12
*1
CA certicate: X.509v1 or X.509v3, DER (encoded binary), PEM
File extension
Key: ".p12" or ".pfx"
CA certicate: ".cer" or ".pem"
Public key algorithm
(and key length)
RSA (512 bits, 1024 bits, 2048 bits, or 4096 bits), ECDSA (P256, P384, P521)
Certicate signatur
e algorithm
SHA1-RSA, SHA256-RSA, SHA384-RSA
*2
, SHA512-RSA
*2
, MD5-RSA, MD2-RSA, SHA1-ECDSA,
SHA256-ECDSA, SHA384-ECDSA, or SHA512-ECDSA
Certicate thumbprint algorithm SHA1
*1
Requir
ements for the certicate contained in a key are pursuant to CA certicates.
*2
SHA384-RSA and SHA512-RSA are available only when the RSA key length is 1024 bits or more.
The machine does not support use of a certicate r
evocation list (CRL).
Denition of "
Weak Encryption"
When <Prohibit Use of Weak Encrypt.> is set to <On>, the use of the following algorithms is prohibited.
Hash: MD4, MD5, SHA-1
HMAC: HMAC-MD5
Common key cryptosystem: RC2, RC4, DES
Public key cryptosystem:
RSA encryption (512 bits/1024 bits), RSA signature (512 bits/1024 bits), DSA (512 bits/1024
bits), DH (512 bits/1024 bits)
Even when <Pr
ohibit Weak Encryp. Key/Cert.> is set to <On>, the hash algorithm SHA-1, which is used for
signing a root certicate, can be used.
Appendix
712
Loading ...
Loading ...
Loading ...