McAfee EPOCDE-AA-BA Product Guide - Page 60

Configuring users for certificate authentication, Problems with certificate authentication

Page 60 highlights

7 Configuring advanced server settings Authenticating with certificates To remove the server certificate, you must disable certificate based authentication. Once a server certificate is uploaded it can only be changed, not removed. Task For option definitions, click ? in the interface. 1 Open the Server Settings page by selecting Menu | Configuration | Server Settings. 2 Select Certificate Based Authentication and click Edit. 3 Deselect Enable Certificate Based Authentication, then click Save. The server settings have been changed, but you must restart the server in order to complete the configuration change. Configuring users for certificate authentication Users must have certificate authentication configured before they can authenticate with their digital certificate. Certificates used for user authentication are typically acquired with a smart card or similar device. Software bundled with the smart card hardware can extract the certificate file. This extracted certificate file is usually the file uploaded in this procedure. Task For option definitions, click ? in the interface. 1 Click Menu | User Management | Users. 2 Select a user and click Actions | Edit. 3 Select Change authentication or credentials, then select Certificate Based Authentication. 4 Use one of these methods to provide credentials. • Copy the DN field from the certificate file and paste it into the Personal Certificate Subject DN Field edit box • Upload a certificate file. Click Browse, navigate to and select the certificate file on your computer, and click OK. User certificates can be PEM- or DER-encoded. The actual certificate format does not matter as long as the format is X.509 or PKCS12 compliant. 5 Click Save to save changes to the user's configuration. The certificate information provided is verified, and a warning is issued if found invalid. From this point on, when the user attempts to log on to ePolicy Orchestrator from a browser that has the user's certificate installed, the log on form is greyed out and the user is immediately authenticated. Problems with certificate authentication Most authentication problems using certificates are caused by one of a small number of problems. If a user cannot log on to ePolicy Orchestrator with their certificate, try one of the following options to resolve the problem: • Verify the user has not been disabled. • Verify the certificate has not expired or been revoked. • Verify the certificate is signed with the correct certificate authority. 60 McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

To remove the server certificate, you must disable certificate based authentication. Once a server
certificate is uploaded it can only be changed, not removed.
Task
For option definitions, click
?
in the interface.
1
Open the Server Settings page by selecting
Menu
|
Configuration
|
Server Settings
.
2
Select
Certificate Based Authentication
and click
Edit.
3
Deselect
Enable Certificate Based Authentication
, then click
Save
.
The server settings have been changed, but you must restart the server in order to complete the
configuration change.
Configuring users for certificate authentication
Users must have certificate authentication configured before they can authenticate with their digital
certificate.
Certificates used for user authentication are typically acquired with a smart card or similar device.
Software bundled with the smart card hardware can extract the certificate file. This extracted
certificate file is usually the file uploaded in this procedure.
Task
For option definitions, click
?
in the interface.
1
Click
Menu
|
User Management
|
Users
.
2
Select a user and click
Actions
|
Edit
.
3
Select
Change authentication or credentials
, then select
Certificate Based Authentication
.
4
Use one of these methods to provide credentials.
Copy the DN field from the certificate file and paste it into the
Personal Certificate Subject DN Field
edit
box
Upload a certificate file. Click
Browse
, navigate to and select the certificate file on your computer,
and click
OK
.
User certificates can be PEM- or DER-encoded. The actual certificate format does not matter as
long as the format is X.509 or PKCS12 compliant.
5
Click
Save
to save changes to the user's configuration.
The certificate information provided is verified, and a warning is issued if found invalid. From this point
on, when the user attempts to log on to ePolicy Orchestrator from a browser that has the user's
certificate installed, the log on form is greyed out and the user is immediately authenticated.
Problems with certificate authentication
Most authentication problems using certificates are caused by one of a small number of problems.
If a user cannot log on to ePolicy Orchestrator with their certificate, try one of the following options to
resolve the problem:
Verify the user has not been disabled.
Verify the certificate has not expired or been revoked.
Verify the certificate is signed with the correct certificate authority.
7
Configuring advanced server settings
Authenticating with certificates
60
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide