HP mt20 Administrator Guide - Page 66

SCEP Manager, DHCP options

Page 66 highlights

Use the Certificate Manager to manually install a certificate from a certificate authority (CA). This action copies the certificate to the user's local certificate store (/usr/local/share/ca-certificates) and configures OpenSSL to use the certificate for connection verification. If desired, use Profile Editor to attach the certificate to a profile, as described in Adding certificates to a client profile on page 63. NOTE: Generally, a self-signed certificate will work as long as it is valid according to specification and can be verified by OpenSSL. SCEP Manager To open the SCEP Manager: ▲ Select Advanced > SCEP Manager in Control Panel. Use the SCEP Manager when you need to enroll or renew client-side certificates from a CA. During an enrollment or renewal, the SCEP Manager generates the thin client's private key and certificate request, and then it sends the request to the CA on the SCEP server. When the CA issues the certificate, the certificate is returned and placed in the thin client's certificate store. OpenSSL uses the certificate for connection verification. NOTE: Before enrollment, make sure that the SCEP server is configured properly. Use the Identifying tab of the SCEP Manager to enter information about the user, if desired. NOTE: The Common Name is required and is the thin client's Fully Qualified Domain Name (FQDN) by default. The other information is all optional. The Country or Region is entered as two letters, such as US for the United States and CN for China. Use the Servers tab of the SCEP Manager to add SCEP servers and enroll or renew certificates. TIP: When entering a new SCEP server, save the server information first, and then use the Settings button to go back and do an enrollment. DHCP options To open the DHCP Option Manager: ▲ Select Advanced > DHCP Options in Control Panel. The DHCP Option Manager displays details of the DHCP options that are requested by the thin client. TIP: The drop-down list in the lower-left corner of the DHCP Option Manager allows you to filter which DHCP tags are displayed. To direct the thin client to request or ignore specific DHCP options: ▲ Select or deselect the checkboxes in the Requested column. If a pencil is shown in the DHCP Code column, the code number can be changed in case there is a conflict on your DHCP server over a particular code number. To change a DHCP code: ▲ Double-click the DHCP code and type a new number. NOTE: Changeable DHCP codes can only be changed while that DHCP option is enabled in the Requested column. 54 Chapter 5 Control Panel

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166

Use the
Certificate
Manager to manually install a
certificate
from a
certificate
authority (CA). This action
copies the
certificate
to the user’s local
certificate
store
(/usr/local/share/ca-certificates)
and
configures
OpenSSL to use the
certificate
for connection
verification.
If desired, use
Profile
Editor to attach the
certificate
to a
profile,
as described in
Adding
certificates
to a client
profile
on page
63
.
NOTE:
Generally, a self-signed
certificate
will work as long as it is valid according to
specification
and can be
verified
by OpenSSL.
SCEP Manager
To open the SCEP Manager:
Select
Advanced > SCEP Manager
in Control Panel.
Use the SCEP Manager when you need to enroll or renew client-side
certificates
from a CA.
During an enrollment or renewal, the SCEP Manager generates the thin client’s private key and
certificate
request, and then it sends the request to the CA on the SCEP server. When the CA issues the
certificate,
the
certificate
is returned and placed in the thin client’s
certificate
store. OpenSSL uses the
certificate
for
connection
verification.
NOTE:
Before enrollment, make sure that the SCEP server is
configured
properly.
Use the
Identifying
tab of the SCEP Manager to enter information about the user, if desired.
NOTE:
The
Common Name
is required and is the thin client’s Fully
Qualified
Domain Name (FQDN) by
default. The other information is all optional. The
Country or Region
is entered as two letters, such as US for
the United States and CN for China.
Use the
Servers
tab of the SCEP Manager to add SCEP servers and enroll or renew
certificates.
TIP:
When entering a new SCEP server, save the server information
first,
and then use the
Settings
button
to go back and do an enrollment.
DHCP options
To open the DHCP Option Manager:
Select
Advanced > DHCP Options
in Control Panel.
The DHCP Option Manager displays details of the DHCP options that are requested by the thin client.
TIP:
The drop-down list in the lower-left corner of the DHCP Option Manager allows you to
filter
which DHCP
tags are displayed.
To direct the thin client to request or ignore
specific
DHCP options:
Select or deselect the checkboxes in the
Requested
column.
If a pencil is shown in the
DHCP Code
column, the code number can be changed in case there is a
conflict
on
your DHCP server over a particular code number.
To change a DHCP code:
Double-click the DHCP code and type a new number.
NOTE:
Changeable DHCP codes can only be changed while that DHCP option is enabled in the
Requested
column.
54
Chapter 5
Control Panel