76
Chapter 3 Using certificates
311644-J Rev 00
9
Enter the reference number and authorization code (provided to the remote
user by the administrator — the administrator gets this information after
entering a new user into the PKI); then click on Next.
The Entrust Certificate PKI Accessibility screen appears.
10
Click on the appropriate button indicating where the Entrust Certificate PKI is
located, or click on I Don’t Know, if that is the case. Then click on Next.
When the PKI server is located on the Internet or behind the firewall, the
server is considered directly accessible. When the PKI server is behind the
Contivity gateway, it is considered to be not directly accessible. The test
option (I Don’t Know where the PKI server is) attempts to establish a TCP
connection to ports 389 and 709 to the PKI listed in the entrust.ini file. It tries
for 30 seconds before timing out. If the connection times out or is refused, the
wizard moves to Step 11, assuming that the PKI is not directly accessible.
11
Select a dial-up connection to dial from the list of Dial-Up Networking
Profiles if a dial-up connection is necessary to access the Internet; then review
the information on the Generate Certificate screen. This screen shows the
information that is used to generate the authentication certificate and appears
only if the PKI server is located behind the firewall. If everything is correct,
click on Finish; a connection to the PKI is established that generates a new
certificate.
This completes the required information when your PKI Entrust Certificate
server is located behind a firewall.
In the situation where the PKI Entrust Certificate server is located behind the
firewall and the Contivity gateway, then you must also provide an LDAP user
ID and password via the User Identification screen. This is needed to establish
a temporary tunnel used only to get a new certificate. When the certificate has
been generated, the user no longer needs the temporary LDAP user ID and
password, since the new certificate is used.
This information must have already been provided to you by the network
administrator. The administrator must have created a special group for this
username and password so that a filter only allows access to the PKI for this
user.
12
Enter the host name or IP address of the remote Contivity gateway; then click
on Next.
The Dialup Connection screen appears.
Содержание Contivity VPN Client
Страница 8: ...8 Contents 311644 J Rev 00 ...
Страница 10: ...10 Figures 311644 J Rev 00 ...
Страница 12: ...12 Tables 311644 J Rev 00 ...
Страница 84: ...84 Chapter 3 Using certificates 311644 J Rev 00 ...
Страница 88: ...88 Appendix A Client logging 311644 J Rev 00 ...