Requiring Client Authentication - Netscape ENTREPRISE SERVER 6.1 - 08-2002 ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Requiring Client Authentication

You can enable the connection groups for your Administration Server and each
server instance to require client authentication. When client authentication is
enabled, the client's certificate is required before the server will send a response to
a query.
Enterprise Server supports authenticating client certificates by matching the CA in
the client certificate with a CA trusted for signing client certificates. You can view a
list of CAs trusted for signing client certificates in the Manage Certificates page
under Security in the Administration Server. There are four types of CAs:
Untrusted CA (will not be matched)
Trusted Server CA (will not be matched)
Trusted Client CA (will be matched)
Trusted Client/Server CA (will be matched)
You can configure the web server to refuse any client that doesn't have a client
certificate from a trusted CA. To accept or reject trusted CAs, you must have set
client trust for the CA. For more information, see "Managing Certificates," on
page 100.
Enterprise Server will log an error, reject the certificate, and return a message to the
client if the certificate has expired. You can also view which certificates have
expired in the Administration Servers Manage Certificates page.
You can configure your server to gather information from the client certificate and
match it with a user entry in an LDAP directory. This ensures that the client has a
valid certificate and an entry in the LDAP directory. It can also ensure that the
client certificate matches the one in the LDAP directory. To learn how to do this,
see "Mapping Client Certificates to LDAP," on page 122.
You can combine client certificates with access control, so that in addition to being
from a trusted CA, the user associated with the certificate must match the access
control rules (ACLs). For more information, see "Using Access Control Files," on
page 170.
You can also process information from client certificates. For more information, see
the Netscape Enterprise Server NSAPI Programmer's Guide.
Setting Client Security Requirements
Chapter 5
Securing Your Enterprise Server
121

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the NETSCAPE ENTREPRISE SERVER 6.1 - 08-2002 ADMINISTRATOR and is the answer not in the manual?

Questions and answers

Subscribe to Our Youtube Channel

This manual is also suitable for:

Entreprise server 6.1

Table of Contents