Configuring with Web Based Management
4.2 Starting the WBM
SINEMA Remote Connect - Server
38
Operating Instructions, 11/2017, C79000-G8976-C383-04
certificate can sign a certificate just like a root certificate, therefore both are "CA certificates".
CA is the acronym for "Certification Authority".
This hierarchy can continue over several intermediate certificates as far as the end entity
certificate. The end entity certificate is the certificate of the user to be identified. In the
remaining description the end entity certificate will be known as PKI certificate
During validation the hierarchy is run through in the opposite direction. As described above
the certificate issuer is identified, the signature checked with the public key, then the
certificate of the higher-level certificate issuer is identified until the trust chain has been run
through as far as the root certificate.
Summary: The chain of intermediate certificates as far as the root certificate must exist on
the SINEMA RC Server that should validate the PKI certificate of the user.
How it works
After the chain of certificates has been installed on the SINEMA RC Server, the user can log
on with his or her PKI certificate. After successfully logging on, a check is made to establish
whether the contained PKI certificate of the user is valid.
Then a check is made as to whether the attributes of the PKI DN filter rules are included in
the PKI certificate.
There are the following types of logon:
●
User identification
if the PKI DN filter rule applies to a user, this user is logged on with the SINEMA RC
Server with the user name, see section "Creating new users (Page 83)".
●
Temporary users
If the PKI filter rule applies to a role, a temporary user is created. pkiuser _X is used as
the user name. The temporary user receives the right and the access to the participant
groups assigned to the role. This user is listed in "User accounts > Users & Roles".
In the role you also specify when the temporary user will be deleted, see section
"Managing role and rights (Page 80)".
Logging on with Smartcard
Requirement
●
A card reader on the PC or notebook
●
The card reader is connected according to the manufacturer's instructions and the driver
belonging to it is installed.
●
The PKI CA certificate chain is installed on the SINEMA RC Server, see section "PKI CA
certificate (Page 96)".
●
A smart card with a valid PKI certificate derived from one of the PKI CA certificates
imported into SINEMA RC.
●
PKI DN filter rules have been created.