Network Integration, Eap-Tls Security Mode - Barco ClickShare CSE-800 Installation Manual

Hide thumbs Also See for ClickShare CSE-800:
Table of Contents

Advertisement

6. CSE-800 Configurator

6.14 Network integration, EAP-TLS security mode

About EAP-TLS
EAP-TLS (Transport Layer Security) is an EAP method based on certificates which allows mutual authentication between client and
server. It requires a PKI (Public Key Infrastructure) to distribute server and client certificates. For some organizations this might be
too big of a hurdle, for those cases EAP-TTLS and PEAP provide good alternatives. Even though a X.509 client certificate is not
strictly required by the standard it is mandatory in most implementations including for ClickShare. When implemented using client
certificates, EAP-TLS is considered one of the most secure EAP methods. The only minor disadvantage, compared to PEAP and
EAP-TTLS, is that the user identity is transmitted in the clear before the actual TLS handshake is performed. EAP-TLS is supported
via SCEP or manual certificate upload.
How to start up for EAP-TLS
1. Log in to the Configurator.
2. Click WiFi & Network → Network integration. Click on Change configuraton.
3. Select the radio button next to EAP-TLS and click Next.
Image 6-27
Network integration, EAP-TLS selected
The EAP-TLS mode window opens.
Two choices are possible:
-
Auto alignment via SCEP
-
Manually provide Client & CA certificates
Image 6-28
Using SCEP
Select the radio button next to Auto enrollment via SCEP and click Next.
The Simple Certificate Enrolment Protocol (SCEP) is a protocol which enables issuing and revoking of certificates in a scalable way.
SCEP support is included to allow a quicker and smoother integration of the ClickShare Base Unit and Buttons into the corporate
network. Since most companies are using Microsoft Windows Server and its active directory (AD) to manage users and devices our
SCEP implementation is specifically targeted at the Network Device Enrolment Service (NDES) which is part of Windows Server
2008 R2 and Windows Server 2012. No other SCEP server implementations are supported.
50
R5900049 CLICKSHARE CSE-800 19/03/2018

Advertisement

Table of Contents
loading

Table of Contents