User's Manual
98
Document #: LTRT-65422
MP-11x & MP-124
9.3
Mutual TLS Authentication
By default, servers using TLS provide one-way authentication. The client is certain that the
identity of the server is authentic. When an organizational PKI is used, two-way
authentication may be desired - both client and server should be authenticated using X.509
certificates. This is achieved by installing a client certificate on the managing PC and
loading the root CA's certificate to the device's Trusted Root Certificate Store. The Trusted
Root Certificate file may contain more than one CA certificate combined, using a text
editor.
Since X.509 certificates have an expiration date and time, the device must be configured to
use NTP (see 'Simple Network Time Protocol Support' on page
101
) to obtain the current
date and time. Without the correct date and time, client certificates cannot work.
To enable mutual TLS authentication for HTTPS:
1.
Set the 'Secured Web Connection (HTTPS)' field to
HTTPS Only
(see 'Configuring
Web Security Settings' on page
69
) to ensure you have a method for accessing the
device in case the client certificate does not work. Restore the previous setting after
testing the configuration.
2.
Open the Certificates page (see 'Replacing the Device's Certificate' on page
95
).
3.
In the
Upload certificate files from your computer
group, click the
Browse
button
corresponding to the 'Send Trusted Root Certificate Store ...' field, navigate to the file,
and then click
Send File
.
4.
When the operation is complete, set the 'Requires Client Certificates for HTTPS
connection' field to
Enable
(see 'Configuring Web Security Settings' on page
69
).
5.
Save the configuration with a device reset (see 'Saving Configuration' on page
324
).
When a user connects to the secured Web interface of the device:
If the user has a client certificate from a CA that is listed in the Trusted Root Certificate
file, the connection is accepted and the user is prompted for the system password.
If both the CA certificate and the client certificate appear in the Trusted Root
Certificate file, the user is not prompted for a password (thus, providing a single-sign-
on experience - the authentication is performed using the X.509 digital signature).
If the user does not have a client certificate from a listed CA or does not have a client
certificate, the connection is rejected.
Notes:
•
The process of installing a client certificate on your PC is beyond the
scope of this document. For more information, refer to your operating
system documentation, and/or consult your security administrator.
•
The root certificate can also be loaded via the Automatic Update facility,
using the HTTPSRootFileName
ini
file parameter.
•
You can enable the device to check whether a peer's certificate has been
revoked by an Online Certificate Status Protocol (OCSP) server (see
Configuring Certificate Revocation Checking (OCSP) on page
99
.
Summary of Contents for Media Pack MP-124
Page 2: ......
Page 14: ...User s Manual 14 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 18: ...User s Manual 18 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 23: ...Part I Getting Started with Initial Connectivity...
Page 24: ......
Page 32: ...User s Manual 32 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 33: ...Part II Management Tools...
Page 34: ......
Page 36: ...User s Manual 36 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 86: ...User s Manual 86 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 88: ...User s Manual 88 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 93: ...Part III General System Settings...
Page 94: ......
Page 103: ...Part IV General VoIP Configuration...
Page 104: ......
Page 130: ...User s Manual 130 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 164: ...User s Manual 164 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 174: ...User s Manual 174 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 199: ...Part V Gateway Application...
Page 200: ......
Page 202: ...User s Manual 202 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 240: ...User s Manual 240 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 286: ...User s Manual 286 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 287: ...Part VI Stand Alone Survivability Application...
Page 288: ......
Page 296: ...User s Manual 296 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 319: ...Part VII Maintenance...
Page 320: ......
Page 326: ...User s Manual 326 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 359: ...Part VIII Status Performance Monitoring and Reporting...
Page 360: ......
Page 389: ...Part IX Diagnostics...
Page 390: ......
Page 404: ...User s Manual 404 Document LTRT 65422 MP 11x MP 124...
Page 417: ...Part X Appendix...
Page 418: ......
Page 580: ...User s Manual 580 Document LTRT 65422 MP 11x MP 124 Reader s Notes...