Configuring External Server Authentication Over Ssl; Figure 10-12: Certificate Management Page - ADTRAN BlueSecure Controller Setup And Administration Manual

Software release version: 6.5
Table of Contents

Advertisement

BSC secure web login page (SSL) - As with any secure web page (SSL), the web
server presents a certificate to authenticate itself with the wireless client. The BSC's
secure web user and administrator login pages contain a default Bluesocket SSL
digital certificate, which is pre-installed on the BSC and cannot be edited or deleted
by the client. For more on login page authentication and how to install the Bluesocket
SSL certificate, see "Installing the Bluesocket SSL Certificate" on page 3-6.
Alternatively, you can acquire an SSL login certificate from another provider and
upload the certificate to the BSC. For more information on uploading an SSL login
certificate from another provider, see "Installing a Custom SSL Login Certificate" on
page 11-22.
Note: Many clients (such as the MSIE7 Web browser) give a warning, or perhaps even
block access, if the partner presents a certificate that specifies a web address for a
Certificate Revocation List (CRL), and the client is unable to access that web address to
see whether the certificate has been listed as revoked, or no longer valid. See
"Uploading a Replacement SSL Certificate You Already Have" on page 11-25for a
description of CRLs and certificates.

Configuring External Server Authentication Over SSL

To configure the BSC to authenticate with an external LDAP/Active Directory, Cosign,
Pubcookie, or CAS server over SSL:
Copy certificate
Copy the external authentication server certificate to your local computer. Usually,
1.
to local
this is either the authentication server digital certificate or the root CA who signed the
computer
server digital certificate.
Note: If the authentication server requires mutual authentication, use your Public Key
Infrastructure (PKI) to create a certificate in PKCS#12 format to load onto the BSC.
The BSC will present this certificate when performing mutual authentication.
Upload
Click the General tab in the BSC administrator console, click the Certificates tab, and
2.
certificate to
then click the Manage link at the top of the page.
BSC
The Certificate Management page appears as shown in Figure 10-12.
Mark the View certificate type radio button for the certificate type to be uploaded.
3.
Typically, you should select either the Trusted server (the LDAP/Active Directory
authentication server digital certificate) or the Trusted CA (the root CA who signed
BlueSecure™ Controller Setup and Administration Guide

Figure 10-12: Certificate Management Page

Digital Certificates
10-21

Advertisement

Table of Contents
loading

Table of Contents