Security Administrator’s Guide
7
no
vd
ocx
(e
n)
6 Ap
ril 20
07
41
7
Security Administrator’s Guide
As with any system, good security requires proper configuration. This section lists
recommendations to ensure that the method functions properly.
7.1 Trusted Root Containers
These containers must include only certificates from trusted Certificate Authorities. Administration
of the certificates in these containers should be restricted.
7.2 Certificate Validation/Revocation Checking
Certificate validation should be enabled and revocation checking properly configured. If a CRL
Grace Period is used, the grace period should be limited to a few days. Do not use the CRL Grace
Period as a mechanism to work around a dysfunctional CRL infrastructure.
7.3 Smart Card Enrollment eDirectory Attributes
Administration of the user attributes used for smart card authentication should be restricted to
administrators who are enrolling smart cards for users.
When matching by subject names, the attributes are:
sasAllowableSubjectNames
nclTmpCertSubject
nclTmpCertExpiration
When matching by certificates, the attributes are:
userCertificate
nclTmpCert
nclTmpCertExpTime
7.4 Certificate Matching
The certificate matching settings should be set to Subject Name matching or Certificate matching.
Certificate matching is more restrictive because it checks the login certificate against the list of
certificates configured for the user. The No Matching option should be used only in specific guest
account scenarios as described in the
Section 5.4.2, “Certificate Matching,” on page 34
.
7.5 Restricting Authentication Methods
Users can be restricted to using the smart card authentication method only. This is accomplished by
restricting the user to a specified NMAS
TM
authentication sequence. The
NMAS Administration
Guide
(http://www.novell.com/documentation/nmas311/index.html)
describes how to do this.
Summary of Contents for Enhanced Smart Card Method 3.0.1
Page 4: ...novdocx en 6 April 2007...
Page 8: ...8 Novell Enhanced Smart Card Method Installation Guide novdocx en 6 April 2007...
Page 10: ...10 Novell Enhanced Smart Card Method Installation Guide novdocx en 6 April 2007...
Page 20: ...20 Novell Enhanced Smart Card Method Installation Guide novdocx en 6 April 2007...
Page 24: ...24 Novell Enhanced Smart Card Method Installation Guide novdocx en 6 April 2007...
Page 28: ...28 Novell Enhanced Smart Card Method Installation Guide novdocx en 6 April 2007...
Page 40: ...40 Novell Enhanced Smart Card Method Installation Guide novdocx en 6 April 2007...
Page 44: ...44 Novell Enhanced Smart Card Method Installation Guide novdocx en 6 April 2007...