Avaya VPN Gateway User Manual page 102

Vpn gateway
Table of Contents

Advertisement

Certificates and Client Authentication
client certificates must therefore also be specified as a CA certificate on the virtual SSL
server.
In addition, the virtual SSL server checks if the client certificate should be revoked, by
comparing the serial number of the presented client certificate with entries in the certificate
revocation list.
The following steps demonstrate how to configure a virtual SSL server to require client
certificates for authentication purposes.
1. Display information about current virtual SSL servers.
2. Configure the chosen virtual SSL server to require client certificates.
3. Specify which CA certificates to use for client authentication.
102
User Guide
This command displays information about all virtual SSL servers on the VPN
Gateway, including installed certificate. Based on the information displayed, decide
which virtual SSL server to configure for client authentication.
cfg/cur ssl
>> Main#
The client must send its client certificate to the virtual SSL server during the SSL
handshake. If the client does not have a certificate, the client will respond with a
NoCertificateAlert message. At that point, the session will be terminated.
server 1
>> SSL#
ssl
>> Server 1#
verify
>> SSL Settings#
Current value: none
Certificate verification (none/optional/require):
Specify which CA certificates you want the virtual SSL server to use for
authenticating client certificates. Only those client certificates that are issued by a
certificate authority whose CA certificate you specify, will be accepted. Note that
the CA certificates you specify by index number must be available on the VPN
Gateway itself.
To authenticate client certificates issued within your own organization, the CA
certificate used for generating the issued client certificates must be specified as a
CA certificate.
cacerts
>> SSL Settings#
""
Current value:
Enter certificate numbers (separated by comma):<CA certificates
by index number>
Comments? infodev@avaya.com
require
April 2013

Advertisement

Table of Contents
loading

This manual is also suitable for:

3050-vmAvg 3050-vm3070-vmAvg 3070-vm3090-vmAvg 3090-vm

Table of Contents