User's Manual
130
Document #: LTRT-10375
Mediant 500 MSBR
loading the root CA's certificate to the device's Trusted Certificates table (certificate root
store). The Trusted Root Certificate file may contain more than one CA certificate
combined, using a text editor.
To enable mutual TLS authentication for HTTPS:
1.
On the Web Settings page (see Configuring Secured (HTTPS) Web on page 79),
configure the 'Secured Web Connection (HTTPS)' parameter to
HTTPS Only
. The
setting ensures that you have a method for accessing the device in case the client
certificate doesn't work. Restore the previous setting after testing the configuration.
2.
In the TLS Contexts table (see Configuring TLS Certificate Contexts on page 117),
select the required TLS Context row, and then click the
Trusted Root Certificates
link located below the table; the Trusted Certificates table appears.
3.
Click the
Import
button, and then select the certificate file.
4.
Wait until the import operation finishes successfully.
5.
On the Web Settings page, configure the 'Require Client Certificates for HTTPS
connection' parameter to
Enable
.
6.
Reset the device with a save-to-flash for your settings to take effect.
When a user connects to the secured Web interface of the device:
If the user has a client certificate from a CA that is listed in the Trusted Root Certificate
file, the connection is accepted and the user is prompted for the system password.
If both the CA certificate and the client certificate appear in the Trusted Root
Certificate file, the user is not prompted for a password (thus, providing a single-sign-
on experience - the authentication is performed using the X.509 digital signature).
If the user does not have a client certificate from a listed CA or does not have a client
certificate, the connection is rejected.
Note:
•
The process of installing a client certificate on your PC is beyond the scope of this
document. For more information, refer to your operating system documentation
and/or consult with your security administrator.
•
The root certificate can also be loaded through the device's Automatic
Provisioning mechanism, using the HTTPSRootFileName
ini
file parameter.
•
You can enable the device to check whether a peer's certificate has been revoked
by an OCSP server per TLS Context (see Configuring TLS Certificate Contexts on
page 117).
13.9 Configuring TLS Server Certificate Expiry Check
You can configure the TLS Server Certificate Expiry Check feature per TLS Context,
whereby the device periodically checks the validation date of installed TLS server
certificates. You can also configure the device to send a notification SNMP trap event
(acCertificateExpiryNotification) at a user-defined number of days before the installed TLS
server certificate is to expire. The trap indicates the TLS Context to which the certificate
belongs.
To configure TLS certificate expiry checks and notification:
1.
Open the TLS Contexts table (see Configuring TLS Certificate Contexts on page 117).
2.
Select the required TLS Context index row, and then click the
Change Certificate
link
located below the table; the Change Certificates page appears.
Summary of Contents for Mediant 500 MSBR
Page 2: ......
Page 33: ...Part I Getting Started with Initial Connectivity ...
Page 34: ......
Page 36: ...User s Manual 36 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 40: ...User s Manual 40 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 45: ...Part II Management Tools ...
Page 46: ......
Page 48: ...User s Manual 48 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 115: ...Part III General System Settings ...
Page 116: ......
Page 132: ...User s Manual 132 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 137: ...Part IV General VoIP Configuration ...
Page 138: ......
Page 290: ...User s Manual 290 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 306: ...User s Manual 306 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 380: ...User s Manual 380 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 454: ...User s Manual 454 Document LTRT 10375 Mediant 500 MSBR This page is intentionallty left blank ...
Page 455: ...Part V Gateway Application ...
Page 456: ......
Page 460: ...User s Manual 460 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 484: ...User s Manual 484 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 494: ...User s Manual 494 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 625: ...Part VI Session Border Controller Application ...
Page 626: ......
Page 654: ...User s Manual 654 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 656: ...User s Manual 656 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 741: ...Part VII Cloud Resilience Package ...
Page 742: ......
Page 751: ...Part VIII Data Router Configuration ...
Page 752: ......
Page 753: ......
Page 754: ......
Page 756: ...User s Manual 756 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 757: ...Part IX Maintenance ...
Page 758: ......
Page 834: ...User s Manual 834 Document LTRT 10375 Mediant 500 MSBR This page is intetnionaly left blank ...
Page 837: ...Part X Status Performance Monitoring and Reporting ...
Page 838: ......
Page 848: ...User s Manual 848 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 852: ...User s Manual 852 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 854: ...User s Manual 854 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 878: ...User s Manual 878 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 880: ...User s Manual 880 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 926: ...User s Manual 926 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 927: ...Part XI Diagnostics ...
Page 928: ......
Page 950: ...User s Manual 950 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 954: ...User s Manual 954 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 956: ...User s Manual 956 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 958: ...User s Manual 958 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 974: ...User s Manual 974 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 976: ...User s Manual 976 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 977: ...Part XII Appendix ...
Page 978: ......
Page 982: ...User s Manual 982 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...