HP t530 Administrator Guide 5 - Page 65

Certificates, Certificate Manager, SCEP Manager, Manageability, Manager

Page 65 highlights

Certificates NOTE: For more information about using certificates in Linux, go to https://www.openssl.org/docs/. Certificate Manager To open Certificate Manager: ▲ Select Security and then select Certificates in Control Panel. Use Certificate Manager to manually install a certificate from a certificate authority (CA). This action copies the certificate to the user's local certificate store (/usr/local/share/ca-certificates) and configures OpenSSL to use the certificate for connection verification. If desired, use Profile Editor to attach the certificate to a profile, as described in Adding certificates to a client profile on page 70. NOTE: Generally, a self-signed certificate will work as long as it is valid according to specification and can be verified by OpenSSL. SCEP Manager To open the SCEP Manager: ▲ Select Security and then select SCEP Manager in Control Panel. Use the SCEP Manager when you need to enroll or renew client-side certificates from a CA. During an enrollment or renewal, the SCEP Manager generates the thin client's private key and certificate request, and then it sends the request to the CA on the SCEP server. When the CA issues the certificate, the certificate is returned and placed in the thin client's certificate store. OpenSSL uses the certificate for connection verification. NOTE: Before enrollment, make sure that the SCEP server is configured properly. Use the Identifying tab of the SCEP Manager to enter information about the user, if desired. NOTE: The Common Name is required and is the Fully Qualified Domain Name (FQDN) of the thin client by default. The other information is all optional. The Country or Region is entered as two letters, such as US for the United States and CN for China. Use the Servers tab of the SCEP Manager to add SCEP servers and enroll or renew certificates. TIP: When entering a new SCEP server, save the server information first, and then use the Settings button to go back and do an enrollment. Manageability Menu option Active Directory Automatic Update Easy Update Description For more information, see Active Directory configuration on page 54. Lets you configure the Automatic Update server manually. For more information, see HP Smart Client Services on page 64. Launches HP Easy Tools. For more information, see the user guide for HP Easy Tools. Manageability 53

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182

Certificates
NOTE:
For more information about using
certificates
in Linux, go to
docs/
.
Certificate
Manager
To open
Certificate
Manager:
Select
Security
and then select
Certificates
in Control Panel.
Use
Certificate
Manager to manually install a
certificate
from a
certificate
authority (CA). This action copies
the
certificate
to the user’s local
certificate
store
(/usr/local/share/ca-certificates)
and
configures
OpenSSL to
use the
certificate
for connection
verification.
If desired, use
Profile
Editor to attach the
certificate
to a
profile,
as described in
Adding
certificates
to a client
profile
on page
70
.
NOTE:
Generally, a self-signed
certificate
will work as long as it is valid according to
specification
and can be
verified
by OpenSSL.
SCEP Manager
To open the SCEP Manager:
Select
Security
and then select
SCEP Manager
in Control Panel.
Use the SCEP Manager when you need to enroll or renew client-side
certificates
from a CA.
During an enrollment or renewal, the SCEP Manager generates the thin client’s private key and
certificate
request, and then it sends the request to the CA on the SCEP server. When the CA issues the
certificate,
the
certificate
is returned and placed in the thin client’s
certificate
store. OpenSSL uses the
certificate
for
connection
verification.
NOTE:
Before enrollment, make sure that the SCEP server is
configured
properly.
Use the
Identifying
tab of the SCEP Manager to enter information about the user, if desired.
NOTE:
The
Common Name
is required and is the Fully
Qualified
Domain Name (FQDN) of the thin client by
default. The other information is all optional. The
Country or Region
is entered as two letters, such as US for
the United States and CN for China.
Use the
Servers
tab of the SCEP Manager to add SCEP servers and enroll or renew
certificates.
TIP:
When entering a new SCEP server, save the server information
first,
and then use the
Settings
button
to go back and do an enrollment.
Manageability
Menu option
Description
Active Directory
For more information, see
Active Directory
configuration
on page
54
.
Automatic Update
Lets you
configure
the Automatic Update server manually.
For more information, see
HP Smart Client Services
on page
64
.
Easy Update
Launches HP Easy Tools.
For more information, see the user guide for HP Easy Tools.
Manageability
53