McAfee MEJCAE-AM-DA Product Guide - Page 152

The ADK tab, The Authentication tab, The Certificates tab, Certificate Authority Type

Page 152 highlights

Using the E-Business Server Administration Utility Getting Started with the E-Business Server Administration Utility console The ADK tab Use the ADK tab to configure how E-Business Server treats Additional Decryption Keys (ADKs). Field Enforce encrypting to ADKs Command-line equivalent --enforce-adk Default ADK --adk-key Warn when encrypting --warn-adk to and ADK See ENFORCE-ADK on page 94 ADK-KEY on page 87 WARN-ADK on page 110 Use to Makes encryption attempts fail if you specify a default ADK (using the Default ADK field or --adk-key command) and E-Business Server cannot find the ADK on your key ring. Specifies a specific Additional Decryption Key (ADK) to use when encrypting messages and generating keys. Make E-Business Server warn users before encrypting to an Additional Decryption Key (ADK). The Authentication tab Use the Authentication tab to define E-Business Server's default behavior when it performs authentication operations. Field Remote Server Username Command-line equivalent --auth-user Remote Server Password --authpassphrase Passphrase file descriptor number --passphrase-fd Conventional passphrase file descriptor number --conventionalpassphrase-fd Allow passphrase retries --allowpassphrase-retry See Use to AUTH-USER on page 89 Specify a user ID for E-Business Server to use when authenticating with a remote user. AUTH-PASSPHRASE on Specify a password for E-Business page 89 Server to use when authenticating with a remote user. PASSPHRASE-FD on page 101 Make E-Business Server read a passphrase from the specified file descriptor. CONVENTIONAL-PASSP HRASE-FD on page 93 Make E-Business Server read a passphrase from the specified file descriptor. Used for conventionally encrypting files. - Make E-Business Server allow users more than one attempt at entering their passphrase. The Certificates tab Use the Certificates tab to set up a Certificate Authority (CA) and basic certificate attributes. Field Certificate Revocation List URL Command-line equivalent --ca-revocation-url Root Certificate --ca-root-cert Certificate Authority URL Certificate Authority Type --ca-url --ca-type Certificate Attributes for --cert-attribute new signatures / certificates Maximum nesting level of trusted introducers --cert-depth See CA-REVOCATION-URL on page 90 CA-ROOT-CERT on page 90 CA-URL on page 90 CA-TYPE on page 90 CERT-ATTRIBUTE on page 90 CERT-DEPTH on page 91 Use to Define the URL used to fetch the Certificate Revocation List (CRL) from the CA. Specify the key ID of the root Certificate Authority's X.509 certificate. Define the default URL used to connect to the Certificate Authority (CA). Identify the type of Certificate Authority (CA) that E-Business Server uses. Specify certificate attributes that E-Business Server will always attach to certificate requests and X.509 signatures. See Supported Certificate Attributes on page 169 for more information. Define the maximum number of levels of nested trusted introducers. E-Business Server™ 8.6 Product Guide 150

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188

E-Business Server
8.6
Product Guide
150
Using the E-Business Server Administration Utility
Getting Started with the E-Business Server Administration Utility console
The ADK tab
Use the
ADK
tab to configure how E-Business Server treats Additional Decryption Keys (ADKs).
The Authentication tab
Use the
Authentication
tab to define E-Business Server’s default behavior when it performs authentication
operations.
The Certificates tab
Use the
Certificates
tab to set up a Certificate Authority (CA) and basic certificate attributes.
Field
Command-line
equivalent
See
Use to
Enforce encrypting to
ADKs
--enforce-adk
ENFORCE-ADK
on
page 94
Makes encryption attempts fail if you
specify a default ADK (using the
Default
ADK
field or
--adk-key
command) and
E-Business Server cannot find the ADK
on your key ring.
Default ADK
--adk-key
ADK-KEY
on page 87
Specifies a specific Additional Decryption
Key (ADK) to use when encrypting
messages and generating keys.
Warn when encrypting
to and ADK
--warn-adk
WARN-ADK
on
page 110
Make E-Business Server warn users
before encrypting to an Additional
Decryption Key (ADK).
Field
Command-line
equivalent
See
Use to
Remote Server
Username
--auth-user
AUTH-USER
on page 89
Specify a user ID for E-Business Server
to use when authenticating with a
remote user.
Remote Server
Password
--auth-
passphrase
AUTH-PASSPHRASE
on
page 89
Specify a password for E-Business
Server to use when authenticating with a
remote user.
Passphrase file
descriptor number
--passphrase-fd
PASSPHRASE-FD
on
page 101
Make E-Business Server read a
passphrase from the specified file
descriptor.
Conventional passphrase
file descriptor number
--conventional-
passphrase-fd
CONVENTIONAL-PASSP
HRASE-FD
on page 93
Make E-Business Server read a
passphrase from the specified file
descriptor. Used for conventionally
encrypting files.
Allow passphrase retries
--allow-
passphrase-retry
Make E-Business Server allow users
more than one attempt at entering their
passphrase.
Field
Command-line
equivalent
See
Use to
Certificate Revocation
List URL
--ca-revocation-url
CA-REVOCATION-URL
on page 90
Define the URL used to fetch the
Certificate Revocation List (CRL) from
the CA.
Root Certificate
--ca-root-cert
CA-ROOT-CERT
on
page 90
Specify the key ID of the root Certificate
Authority’s X.509 certificate.
Certificate Authority
URL
--ca-url
CA-URL
on page 90
Define the default URL used to connect
to the Certificate Authority (CA).
Certificate Authority Type
--ca-type
CA-TYPE
on page 90
Identify the type of Certificate Authority
(CA) that E-Business Server uses.
Certificate Attributes for
new signatures / certificates
--cert-attribute
CERT-ATTRIBUTE
on
page 90
Specify certificate attributes that
E-Business Server will always attach to
certificate requests and X.509
signatures.
See
Supported Certificate Attributes
on
page 169
for more information.
Maximum nesting level of
trusted introducers
--cert-depth
CERT-DEPTH
on
page 91
Define the maximum number of levels of
nested trusted introducers.