Polycom RealPresence Group Series Administrator's Manual page 108

Hide thumbs Also See for RealPresence Group Series:
Table of Contents

Advertisement

Certificate Signing Request Requirements
Whether you need to generate a client-type CSR, a server-type CSR, or both depends on which features
and services you intend to use, and whether your network environment supports certificate-based
authentication for those services. In most cases, both certificates are needed for RealPresence Group
Series systems.
For example, if your system is configured to use any of the following features, and the servers providing
those services perform certificate-based authentication before allowing access to them, you must create a
client-type CSR and add the resulting certificate signed by the CA:
RealPresence Resource Manager system Provisioning
RealPresence Resource Manager system Monitoring
RealPresence Resource Manager system LDAP Directory
RealPresence Resource Manager system Presence
Calendaring
SIP
802.1X
The system web server uses the server-type CSR and resulting certificate whenever a user attempts to
connect to the system web interface. The web server does so by presenting the server certificate to the
browser to identify the system to the browser as part of allowing the browser to connect to the system.
The browser's user needs the server certificate if he or she wants to be certain about the identity of the
system he or she is connecting to. Settings in the web browser typically control the validation of the
server certificate, but you can also validate the certificate manually.
To obtain a client or server certificate, you must first create a CSR. You can create one client and one
server CSR and submit each to the appropriate CA for signing. After the CSR is signed by a CA, it
becomes a certificate you can add to the system.
Related Links
Security Certificates for RealPresence Touch
Certificate Revocation
on page 111
Related Links
Configure Certificate Validation Settings
Install Certificates
on page 110
Configure the CRL Method
Create a Certificate Signing Request
You can create server and client CSRs to identify your system to your network peers.
Procedure
1. In the system web interface, go to Admin Settings > Security > Certificates > Certificate
Options.
2. Click Create for the type of CSR you want to create, Signing Request Server or Signing
Request Client.
The procedure is the same for server and client CSRs.
3. Configure these settings on the Create Signing Request screen and click Create.
Polycom, Inc.
on page 224
on page 109
on page 112
Securing the System
106

Advertisement

Table of Contents
loading

Table of Contents