R5900120 /01
CX-50 Gen2
94
SCEP Server
: This is the IP or hostname of the Windows Server in your network running the NDES service.
Only http is allowed. E.g.: http://myserver or http://10.192.5.1
SCEP username
: This is a user in your Active Directory which has the required permission to access the
NDES service and request the challenge password. To be sure of this, the user should be part of the CA
Administrators group (in case of a stand-alone CA) or have enrol permissions on the configured certificate
templates.
SCEP Password:
The corresponding password for the SCEP username that you are using to authenticate on
service.
Common Name
: The identity you want to link to the certificate.
Image 6–31 LAN Settings, Wireless Client, EAP-TLS, NDES
SCEP requires the following parameters:
SCEP Server
: This is the IP or hostname of Server the server running the SCEP service with the port and
suffix appended. Only http is allowed. E.g.: http://myserver:8080/scep or http://10.192.5.1/test
SCEP Challenge
: The corresponding SCEP challenge password.
Common Name
: The identity you want to link to the certificate.
Image 6–32 LAN Settings, Wireless Client, EAP-TLS, SCEP
6.20 LAN Settings, EAP-TTLS security mode
About EAP-TTLS
EAP-TTLS (Tunneled Transport Layer Security) is an EAP implementation by Juniper networks. It is designed
to provide authentication that is as strong as EAP-TLS, but it does not require each user to be issued a
certificate. Instead, only the authentication servers are issued certificates. User authentication is performed by
password, but the password credentials are transported in a securely encrypted tunnel established based
upon the server certificates.
User authentication is performed against the same security database that is already in use on the corporate
LAN: for example, SQL or LDAP databases, or token systems. Since EAP-TTLS is usually implemented in
corporate environments without a client certificate we have not included support for this. If you prefer using
client certificates per user we suggest using EAP-TLS.
How to setup EAP-TTLS
1.
Select Authentication Mode
EAP-TTLS
.
Summary of Contents for CX-50 Gen2
Page 1: ...ENABLING BRIGHT OUTCOMES Installation manual CX 50 Gen2...
Page 2: ......
Page 10: ......
Page 14: ...R5900120 01 CX 50 Gen2 14...
Page 15: ...15 R5900120 01 CX 50 Gen2 Introduction 1...
Page 28: ...R5900120 01 CX 50 Gen2 28 Getting started...
Page 58: ...R5900120 01 CX 50 Gen2 58 CX 50 Gen2 Installation...
Page 119: ...119 R5900120 01 CX 50 Gen2 Firmware updates 7...
Page 121: ...121 R5900120 01 CX 50 Gen2 Troubleshooting 8...
Page 143: ......