Prima IP User Manual Rev 1.5 2007
- -
21
Security level 3:
offers a secure SSL connection with encryption for mouse, keyboard, and video, and uses
1024-bit PKI-authentication. It should be reserved for very high security applications. It is based on
certificates and 1024-bit RSA keys. The individual keys are protected by passphrases that come in addition
to user passwords. The viewer identifies the PRIMA IP certificate and PRIMA IP identifies each user
certificate. Special sets of PKI certificates and keys must be installed into PRIMA IP and into each computer
that wants to connect to PRIMA IP. Normally, each user is given a proprietary certificate and he is the only
one who knows the passphrase. This mode is highly secure but a little bit constraining for users. As a user,
you must install your certificate into the computer(s) you will use to access PRIMA IP. You must type you
passphrase each time you login. This passphrase cannot be filled out automatically by the viewer or the
browser.
The choice of a security level to be implemented for the PRIMA IP viewer connection is of most importance,
especially when your remote server connections require high security to keep your servers safe from
unauthorized entries and/or network sniffers.
If you choose to implement the PKI authentication feature, select
Level 3 viewer security connection
on the
Security
page.
Into
KVM Server Password,
enter the password for the server private key serverkey.pem (
serverpwd
for
the set of certificates provided on the Support CDROM). Refer to next section for more information about
PRIMA IP certificates
.
Click
Store Settings
to save your settings and go to the
Apply Settings
page to make them active.
2.7.3 Installing Certificates and Key on PRIMA IP for Security level 3
You do not need to install any certificate unless you plan to use the security level 3 (refer to previous section).
You can skip this section if you plan to use the security level 1 or 2.
You can use the default set of certificates (provided on the CD-ROM) for training. However, it is
not recommended to work with these certificates because anybody who has got a copy of them
might establish a connection to your servers. Therefore, we recommend you obtain your own
certificates from a public Certificate Authority or you generate a private set by using some CA
software such as XCA.
For certificate generation and certificate characteristics, please refer to "How to Generate PRIMA IP
Certificates using XCA" (can be found on the PRIMA IP support CD-ROM)
.