Configuring Security Settings : About the SCC certificate authority service
  
About the SCC certificate authority service
SCC Certificate Authority settings are under Administration > Security: Certificate Authority. The SCC includes a certificate authority (CA) service. You can configure the SCC CA as a private root CA or an intermediate CA that is trusted within your organization. The SCC CA service enables you to issue these types of certificates to managed appliances:
Secure peering certificates
Proxy certificates for SSL optimization
Web proxy certificates for HTTPS traffic proxy.
Managing certificates for secure protocol optimization and HTTPS web proxy can be daunting and time-consuming. The SCC CA service provides a way to simplify, streamline and automate certificate management from the SCC Management Console. Using the SCC CA service, you can:
manage and issue secure peering certificates to managed appliances.
configure secure peering trust relationships between managed appliances for secure protocol optimization.
Using SCC to configure and manage secure peering trust relationships among managed appliances eliminates the need to configure those relationships on each appliance, one at a time. When you replace the secure peering certificate on a managed appliance with a certificate issued by the SCC CA, the SCC CA becomes a trusted entity on that managed appliance. Subsequently, that appliance automatically trusts all peers that have a issued by the same SCC.
The SCC CA can only be used to issue certificates and implicitly signs all certificates it issues. Using and trusting only CA-signed certificates increases the security of your fleet of managed appliances. You can't submit a Certificate Signing Request (CSR) through the SCC Management Console to have a certificate signed by the SCC CA. The CA purpose must be set to TRUE to use it with the SCC CA service. Here’s an example for a root certificate where the extension is a CA:
X509v3 extensions:
X509v3 Key Usage:
Digital Signature, Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE
X509v3 Subject Key Identifier:
8F:XX:A1:E6:XX:FC:D4:DD:XX:XX:04:05:D5:07:9B:6C:XX:XX:FA:B.1.3.6.1.4.1.31