Table 10-8
Options on the
TLS
tab (continued)
Description
Option
These are the issuers of the client certificates that the Intel AMT
device recognizes as authentic. These certificates are stored in the
database and then sent to the Intel AMT device during configuration.
Intel AMT can accept up to four trusted root certificates, so no more
than four should be added to a profile.
Click the Add symbol and, in the Select Trusted Root Certificate
dialog box, select the certification authority (CA) that you configured
to issue certificates for TLS with Mutual.
You can also import the trusted root CA certificate from a file.
See
“About TLS”
on page 95.
Trusted
Certificates
(Optional)
The Certificate Revocation List (CRL) is a list of entries that indicate
which certificates have been revoked. The CRL contains certification
authority URLs and the serial numbers of revoked certificates. This
is an optional feature of TLS Mutual Authentication.
Click the Manage CRL symbol to define a CRL.
CRL
The Fully Qualified Domain Name (FQDN) suffixes for mutual
authentication.
The Intel AMT device validates that any client certificates that Intel
SCS or Altiris solutions use have one of the listed suffixes in the
certificate subject.
Type the FQDN suffix of the Notification Server computer: for
example, type
yourenterprise.com
. If you want to type more than
one suffix, use a comma as a delimiter.
FQDN Suffixes
TLS: Edit CRL dialog box
The Certificate Revocation List (CRL) is a list of entries that indicate which
certificates have been revoked. The CRL contains certification authority URLs
and the serial numbers of revoked certificates. CRL is an optional feature of TLS
Mutual Authentication.
This feature requires a certification authority be installed in your environment.
See
“Installing and configuring CA”
on page 36.
Add and select the CRL that you want to use.
About Out of Band Management Component pages
Configuration Profiles page
136