Authentication Schemes 85
• Password entry
Where more than one Authentication Scheme has been defined, the first Login page will have:
• Language selection
• Username entry
Once the Login button is selected a second page is presented to the user where it is possible to choose
an Authentication Scheme by clicking the here hyperlink. This action will load the schemes page
where any defined scheme is selectable. When selected with the OK button the user is returned back
to the Login page with the selected Authentication Scheme activated.
SSL Client Certificate Authentication
SSL Client Certificate Authentication can be seen as the next progression in the authentication
modules. It is more secure than the previous modules but requires a little more configuration. To some
degree, Client Certificate Authentication is an automatic authentication process requiring minimal
interaction from the user. All the user is required to do is to install the certificate into the browser the
first time that it is installed and then just select that certificate when prompted on future logon
attempts. Everything else is performed by the browser and server.
A certificate is generated and validated before being imported into the client’s browser. When this
browser connects to the appliance the two begin instantly exchanging secure information to try and
identify one another. The browser uses this certificate as a means of authenticating itself to the server.
The server, aware of the provided certificate, is able to verify the client and automatically grant
authentication.
Since a unique certificate can be assigned to each user, Client Certificates can provide a very secure
means of access. Unlike the previous authentication methods, Client Certificates requires a bit more
configuring but this only has to be done once. The general process is highlighted below.
• Enable Authentication
• Create a CA
• Create Client Certificate(s)
• Import Certificate(s) into Browser
The certificate is tied into the browser which means that anyone using this machine can log into the
system if they are using the same user account on the local machine. A primary authentication module
should be used in conjunction with client certificate authentication such as password authentication
to tighten access.
Before all these however, an Authentication Module should be available, which has client certificates
included. Once these are all done, using certificates is a simple process.
1.
All the administrator needs to do is enable the Authentication Scheme. A user selecting this
scheme will force the browser to begin using the certificate to authenticate itself.
2.
Once the authentication process begins the Choose a digital certificate dialog will appear. Select
the appropriate certificate you wish to use then OK or Cancel if you do wish to use any.
3.
If successful a message is displayed showing that the SSL client certificate is valid and the client
will now be able to access the system.
Содержание SSL VPN
Страница 8: ...viii Barracuda SSL VPN Administrator s Guide...
Страница 34: ...34 Barracuda SSL VPN Administrator s Guide...
Страница 76: ...76 Barracuda SSL VPN Administrator s Guide...
Страница 94: ...94 Barracuda SSL VPN Administrator s Guide...
Страница 98: ...98 Barracuda SSL VPN Administrator s Guide...
Страница 104: ...104 Barracuda SSL VPN Administrator s Guide...
Страница 110: ...110 Barracuda SSL VPN Administrator s Guide...