primos User Manual
Security
56
Requirements
primos is defined as user (with user name and password) on a RADIUS server.
1. Start the primos Control Center.
2. Select
SECURITY – Authentication
.
3. Select
MD5
from the
Authentication method
list.
4. Enter the
User name
and
Password
that are used for the configuration of primos on
the RADIUS server.
5. Click
Save
to confirm.
The settings are saved.
Configuring EAP-TLS
Benefits and
Purpose
EAP-TLS (Transport Layer Security) validates the identity of devices or users before they
gain access to network resources. You can configure primos for the EAP-TLS network
authentication. This makes sure that primos gets access to protected networks.
Mode of
Operation
EAP-TLS describes a certificate-based authentication method via a RADIUS server. For this
purpose, certificates are exchanged between primos and the RADIUS server. An
encrypted TLS connection between primos and the RADIUS server is established in this
process. Both RADIUS server and primos need a valid, digital certificate signed by a CA.
The RADIUS server and primos must validate the certificate. After the mutual
authentication was successful, the access to the network will be freed.
Since each device needs a certificate, a PKI (Public Key Infrastructure) must be available.
User passwords are not necessary.
If you want to use the EAP-TLS authentication, you must observe the instructions below
in the indicated order. If this procedure is not adhered to, primos may not be addressable
in the network. In this case you have to reset the configuration settings of primos (
Procedure
• Create a certificate request in primos
• Create a certificate using the certificate request and the authentication server.
• Install the requested certificate in primos
• Install the root CA certificate of the certification authority that has issued the
certificate of the authentication server (RADIUS) in primos
• Enable the authentication method 'EAP-TLS' in primos.
1. Start the primos Control Center.
2. Select
SECURITY – Authentication
.
3. Select
TLS
from the
Authentication method
list.
4. From the list
EAP root certificate
, select the root CA certificate.
5. Enter the password that is used for the configuration of primos on the RADIUS server.
Summary of Contents for primos
Page 1: ...User Manual...