Configuring with Web Based Management
4.9 Security
SINEMA Remote Connect - Server
Operating Instructions, 11/2017, C79000-G8976-C383-04
97
PKI DN blacklist
The user is blocked if a suitable PKI DN filter rule exists in the PKI DN blacklist.
1.
Click on the "PKI DN Blacklist" tab.
2.
Enter the corresponding rule in "PKI DN filter rule". The attributes of the names
(Distinguished Name acc. to the X.509 standard) are used as filter criteria. This requires
that the attributes are included in the PKI certificate of the user. For more detailed
information, refer to the section "Logon with the Smartcard / PKI certificates".
3.
Click "Add".
Result:
The created entries are listed on the page:
Box
Meaning
DN filter
Shows the PKI DN filter rule.
Deactivated user
Displays the users to which the rule applies and that are therefore
blocked.
Delete
Deletes the entry
Certificate revocation list
The output certificates that are no longer valid are listed in the certificate revocation list. If,
for example, employees leave the company, their certificates are called back and included in
the list. Logging on with this certificate is then no longer possible.
So that the revocation list is used, activate the CRL check on the "Settings" tab.
On the "Revocation list" tab, you can see an overview of the available revocation lists:
Box
Meaning
Issuer
Display of the certification authority that issued the certificate revocation
list.
Status
Shows whether the certificate revocation list is valid or has already
expired.
Revoked Serial numbers
Shows the revoked serial numbers.
Valid from
Date from which the certificate revocation list is valid.
Valid to
Date up to which the certificate revocation list is valid.
Last update
Date on which the certificate revocation list was last updated.
Next update
Date on which the certificate revocation list will next be updated.
Origin
Shows where the certificate revocation list originates from:
File: The certificate revocation list was imported
URL: The certificate revocation list is stored at the distribution point.