primos User Manual
Security
57
6. Click
Save
to confirm.
The settings are saved.
Configuring EAP-TTLS
Benefits and
Purpose
EAP-TTLS (Tunneled Transport Layer Security) validates the identity of devices or users
before they gain access to network resources. You can configure primos for the EAP-TTLS
network authentication. This makes sure that primos gets access to protected networks.
Mode of
Operation
EAP-TTLS consists of two phases:
In phase 1, a TLS-encrypted channel between primos and the RADIUS server will be
established. Only the RADIUS server authenticates itself to primos using a certificate that
was signed by a CA. This process is also referred to as 'outer authentication'.
In phase 2, an additional authentication method is used for the communication within
the TLS channel. EAP-defined methods and older methods (CHAP, PAP, MS-CHAP and MS-
CHAPv2) are supported. This process is also referred to as 'inner authentication'.
The advantage of this procedure is that only the RADIUS server needs a certificate.
Therefore no PKI is needed. Moreover, TTLS supports most authentication protocols.
Requirements
primos is defined as user (with user name and password) on a RADIUS server.
1. Start the primos Control Center.
2. Select
SECURITY – Authentication
.
3. Select
TTLS
from the
Authentication method
list.
4. From the list
EAP root certificate
choose the root CA certificate of the certification
authority that has issued the certificate of the authentication server (RADIUS).
(Optional) The certificate increases the security when establishing the connection.
(The root CA certificate must have been installed in primos previously
.)
5. In the
Anonymous name
box enter the name for the unencrypted part of the EAP-
TTLS authentication.
6. From the list
Inner authentication
choose the method intended to secure the com-
munication in the TLS channel.
7. Enter the
User name
and
Password
that are used for the configuration of primos on
the RADIUS server.
8. Install a WPA add-on. (Optional)
9. Click
Save
to confirm.
The settings are saved.
Содержание primos
Страница 1: ...User Manual...