
3-54
Initial Setup of the ProCurve NAC 800
Digital Certificates
Digital Certificates
Your ProCurve NAC 800 (or NAC 800s) might require a digital certificate for
several reasons:
■
On a CS or MS, an SSL certificate enables access to the Web browser
interface. (HTTPS, the only supported option, requires the server to have
a certificate).
■
A CS or ES requires an SSL certificate to communicate with endpoints
during endpoint integrity testing.
■
A NAC 800 acting as a RADIUS server (CS or ES) requires a server
certificate for:
•
Server authentication
—The NAC 800 authenticates itself during
the Extensible Authentication Protocol (EAP) process.
•
Client authentication
—The NAC 800 and the endpoint can use the
certificate to generate keys to secure the EAP process. Depending on
the EAP method, the NAC 800 also verifies end-users’ certificates.
■
A NAC 800 that binds to a Lightweight Directory Access Protocol (LDAP)
server that uses TLS authentication requires the CA root certificate for
the LDAP server’s CA.
The instructions in this section apply only to the first and second purposes.
To learn about configuring digital certificates for the other purposes, see
Chapter 4: “Configuring the RADIUS Server—Integrated with ProCurve Iden-
tity Driven Manager” or Chapter 5: “Configuring the RADIUS Server—Without
Identity Driven Manager.”
At factory defaults, a NAC 800 uses a self-signed digital certificate for HTTPS.
In this certificate,
cn=HP
. You will probably want to install a new certificate
that:
■
Includes information about this specific device and your own organization
■
Is signed by your company’s CA or by a trusted CA
See “Install a CA-Signed Certificate for HTTPS” on page 3-55 to learn how to
obtain and install a signed certificate for HTTPS.
You can also create a new self-signed certificate for HTTPS. See “Install a New
Self-Signed Certificate for HTTPS” on page 3-61.
Содержание 800
Страница 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Страница 2: ......
Страница 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Страница 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Страница 145: ...3 17 Initial Setup of the ProCurve NAC 800 System Settings Figure 3 9 Home System Configuration Management Server ...
Страница 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Страница 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Страница 328: ...5 64 Configuring the RADIUS Server Without Identity Driven Manager Manage Digital Certificates for RADIUS ...
Страница 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Страница 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Страница 380: ...A 26 Appendix A Glossary ...
Страница 394: ...B 14 Appendix B Linux Commands Service Commands ...
Страница 405: ......
Страница 406: ... Copyright 2007 2008 Hewlett Packard Development Company L P April 2008 Manual Part Number 5991 8618 ...