Hp Secure Key Manager Manuel d'utilisateur Page 172

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 327
  • Table des matières
  • DEPANNAGE
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 171
Table 81 KMS Server Authentication Settings section components
Component Description
User Directory
This eld determines whether the KMS Server uses a local user and groups directory
for this device
or a central LDAP server. You can only choose one user directory at a
time; if you ch
oose LDAP, any local users or groups you dene will be unavailable.
NOTE:
Selecting LDAP on a FIPS-compliant device will take the device out of FIPS
compliance - possibly in a manner that does not comply with FIPS standards.
For informati
on on disabling FIPS compliance, see FIPS Compliance.
Password
Authentication
This eld determines whether you require users to provide a username and password
to access the KMS Server. Doing so effectively disables global sessions. You have
two choices for this eld:
Optional – no password authentication is required; global sessions are allowed;
unauthenticated users can create global keys; all users can access global keys;
only authenticated users can create and access non–global keys.
Required – password authentication is required; global sessions are not allowed;
only non–global keys can be created; authenticated users can access global
and non–global keys.
Client Certicate
Authentication
You have three options for client certicate authentication:
Not used clients do not have to provide a client certicate to authenticate to
the KMS Server.
Used for SSL session only –clientsmustprovideacerticate signed by a CA
trustedbytheSKMinordertoestablishanSSLconnection.Whenyouselectthis
option, you must also select a Trusted CA List Prole.
Used for SSL session and username –again,clientsmustprovideacerticate
signed by a CA trusted by the SKM in order to establish an SSL session with
the KMS Server; additionally, a username is derived from the client certicate.
That username is the sole means of authentication if password authentication
is optional and the client does not provide a username and password. If the
client provides a username, the KMS Server compares the username derived
from the certicate against the username in the authentication request. If the
usernames are the same and the password is valid, the user is authenticated. If
the usernames are not the same, the connection is closed immediately. When
youselectthisoption,youmustalsoselectaTrustedCAListProle, and you must
choose the eld from which the username is derived.
Trusted CA List Prole
This eld allows you to select a prole to use to verify that client certicates are
signedbyaCAtrustedbytheSKM.Thisoptionisonlyvalidifyourequireclientsto
pro
vide a certicate to authenticate to the KMS Server. For more information, see
Tru
sted Certicate Authority List Proles. As delivered, the default Trusted CA List
pr
ole contains no CAs. You must either add CAs to the default prole or create a
ne
wprole and populate it with at least one trusted CA before the KMS Server can
au
thenticate client certicates.
Username Field in
Client Certicate
This option allows you to specify the certicate eldfromwhichtheusernameis
derived. The username can be derived from the UID (user ID), CN (Common
Name), SN (Surname), E (Email address), E_ND (Email without domain), or OU
(Organizational Unit) eld. When you select the E_ND option, the KMS Server
matches against the data to the left of the @ symbol in the E-mail address in the
certicate request. For example, if the certicate request contains the E-mail address
User1@company.com, then the KMS Server matches against User1.
Require Client
Certicate to Contain
Source IP
When this option is enabled, the KMS Server expects that the client certicate
presented by the client application has an IP address in the subjectAltName eld.
The KMS Server obtains the IP address from the subjectAltName and compares that
to the source IP address of the client application; if the two IP addresses match, the
KMS Server authenticates the user. If the two IP addresses do not match, the KMS
Server closes the connection with the client.
Edit Click Edit to modify the KMS Server authentication settings.
172
Using the Management Console
Vue de la page 171
1 2 ... 167 168 169 170 171 172 173 174 175 176 177 ... 326 327

Commentaires sur ces manuels

Pas de commentaire