>> User#
edit cert_admin
>> User cert_admin#
password
Enter admin's current password:(admin user password)
Enter new password for cert_admin:(cert_admin user password)
Re-enter to confirm:(reconfirm cert_admin user password)
7. Apply the changes.
>> User cert_admin#
apply
Changes applied successfully.
8. Let the Certificate Administrator user define an export passphrase.
This step is only necessary if you want to fully separate the Certificate Administrator
user role from the Administrator user role. If the admin user is removed from the
certadmin group, a Certificate Administrator export passphrase (caphrase) must be
defined.
As long as the admin user is a member of the certadmin group (the default
configuration), the admin user is prompted for an export passphrase each time a
configuration backup that contains private keys is sent to a TFTP/FTP/SCP/SFTP
server (command:
/cfg/ptcfg
). When the admin user is not a member of the
certadmin group, the export passphrase defined by the Certificate Administrator is
used instead to encrypt private keys in the configuration backup. The encryption of
private keys using the export passphrase defined by the Certificate Administrator
is performed transparently to the user, without prompting. When the configuration
backup is restored, the Certificate Administrator must enter the correct export
passphrase.
Note:
If the export passphrase defined by the Certificate Administrator is lost,
configuration backups made by the admin user while he or she was not a member
of the certadmin group cannot be restored.
Note:
When using the
/cfg/ptcfg
command on an ASA 310-FIPS, private keys are
always encrypted using the wrap key that was generated when the first HSM card
in the cluster was initialized.
The export passphrase defined by the Certificate Administrator remains the same
until changed by using the
/cfg/sys/user/caphrase
command. For users who
are not members of the certadmin group, the
caphrase
command in the User menu
is hidden. Only users who are members of the certadmin group should know the
export passphrase. The export passphrase can contain spaces and is case
sensitive.
Managing Users and Groups
78 User Guide
April 2013
Comments? infodev@avaya.com
Summary of Contents for 3050-VM
Page 1: ...User Guide Avaya VPN Gateway Release 9 0 NN46120 104 Issue 04 04 April 2013 ...
Page 4: ...4 User Guide April 2013 Comments infodev avaya com ...
Page 12: ...12 User Guide April 2013 ...
Page 20: ...New in this release 20 User Guide April 2013 Comments infodev avaya com ...
Page 30: ...Introducing the VPN Gateway 30 User Guide April 2013 Comments infodev avaya com ...
Page 36: ...Introducing the ASA 310 FIPS 36 User Guide April 2013 Comments infodev avaya com ...
Page 74: ...Upgrading the AVG Software 74 User Guide April 2013 Comments infodev avaya com ...
Page 86: ...Managing Users and Groups 86 User Guide April 2013 Comments infodev avaya com ...
Page 130: ...The Command Line Interface 130 User Guide April 2013 Comments infodev avaya com ...
Page 162: ...Supported Ciphers 162 User Guide April 2013 Comments infodev avaya com ...
Page 212: ...Syslog Messages 212 User Guide April 2013 Comments infodev avaya com ...
Page 242: ...Definition of Key Codes 242 User Guide April 2013 Comments infodev avaya com ...
Page 259: ...Creating a Port Forwarder Authenticator User Guide April 2013 259 ...
Page 266: ...Using the Port Forwarder API 266 User Guide April 2013 Comments infodev avaya com ...
Page 274: ...X 509 274 User Guide April 2013 Comments infodev avaya com ...