219
1.877.877.2269
BLACKBOX.COM
NEED HELP?
LEAVE THE TECH TO US
LIVE 24/7
TECHNICAL
SUPPORT
1.877.877.2269
CHAPTER 10: AUTHENTICATION
Service-Type = Framed-User,
Fall-Through = No,
Framed-Filter-Id =":group_name=admin:"
The list of groups may include any number of entries separated by a comma. If the admin group is included, the user will be made
an Administrator.
If there is already a Framed-Filter-Id, add the list of group_names after the existing entries, including the separating colon :.
10.3 SSL CERTIFICATE
The console server uses the Secure Socket Layer (SSL) protocol for encrypted network traffic between itself and a connected user.
During connection establishment, the console server has to expose its identity to the user’s browser using a cryptographic certificate.
The default certificate that comes with the console server device upon delivery is for testing purposes only and should not be relied on for
secure global access.
NOTE: System administrators must not rely on the default certificate as the secured global access mechanism for use through Internet.
Switch to your preferred browser.
Enter https://ip-address-or-hostname-of-console-server-here/.
Your browser may respond with a message that verifies the security certificate is valid but notes that it is not necessarily verified by
a certifying authority.
To proceed, you need to click yes if you are using Internet Explorer or select accept this certificate permanently (or temporarily) if
you are using Mozilla Firefox.
The Management Console login will present.
Enter an Administrator’s username and password as normal .
NOTE: We recommend that you generate and install a new base64 X.509 certificate that is unique for each particular console server.
To generate a new base64 X.509 certificate, the console server must be enabled to generate a new cryptographic key and the
associated Certificate Signing Request (CSR) that needs to be certified by a Certification Authority (CA).
A certification authority verifies that you are the person who you claim you are, and signs and issues a SSL certificate to you. To
create and install a SSL certificate for the console server:
Navigate to System > SSL Certificate.
Fill out the presented fields.
Common name: the network name of the console server once it is installed in the network. Usually the fully qualified domain name.
It is identical to the name used to access the console server with a web browser (without the “http://” prefix). If the name given here
and the actual network name differ, the browser will pop up a security warning when the console server is accessed using https.
Organizational Unit: this field is used for specifying to which department within an organization the console server belongs.
Organization: the name of the organization to which the console server belongs.
Locality/City: the city where the organization is located.
State/Province: the state or province where the organization is located.
Country: the two-letter ISO code designating the country where the organization is located.
For example, DE for Germany and US for the the United States of America.
NOTE: The country code must be entered in ALL CAPS.
Email: the email address of the person responsible for the console server and its security.
Challenge Password: some certification authorities require a challenge password to authorize later changes on the certificate
(for example, revocation of the certificate).