04.03.2013 Views

OfficeScan 10.6 Administrator's Guide - Trend Micro™ Online Help

OfficeScan 10.6 Administrator's Guide - Trend Micro™ Online Help

OfficeScan 10.6 Administrator's Guide - Trend Micro™ Online Help

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Cisco Secure ACS Server Enrolment<br />

Using Policy Server for Cisco NAC<br />

Enroll the Cisco Secure ACS server with the Certificate Authority (CA) server to<br />

establish a trust relationship between the two servers. The following procedure is for<br />

users running a Windows Certification Authority server to manage certificates on the<br />

network. Refer to the vendor documentation if using another CA application or service<br />

and see the ACS server documentation for instructions on how to enroll a certificate.<br />

CA Certificate Installation<br />

The <strong>OfficeScan</strong> client authenticates with the ACS server before it sends security posture<br />

data. The CA certificate is necessary for this authentication to take place. First, export<br />

the CA certificate from the CA server to both the ACS server and the <strong>OfficeScan</strong> server,<br />

then create the CTA agent deployment package. The package includes the CA certificate<br />

(see The CA Certificate on page 15-19 and Cisco Trust Agent Deployment on page 15-27).<br />

Perform the following to export and install the CA certificate:<br />

• Export the CA certificate from the Certificate Authority server<br />

• Install it on the Cisco Secure ACS server<br />

• Store a copy on the <strong>OfficeScan</strong> server<br />

Note: The following procedure is for users running a Windows Certification Authority<br />

server to manage certificates on the network. Refer to the vendor documentation if<br />

you use another Certification Authority application or service.<br />

To export and install the CA certificate for distribution:<br />

1. Export the certificate from the Certification Authority (CA) server:<br />

a. On the CA server, click Start > Run. The Run screen opens.<br />

b. Type mmc in the Open box. A new management console screen opens.<br />

c. Click File > Add/Remove Snap-in. the Add/Remove Snap-in screen<br />

appears.<br />

d. Click Certificates and click Add. The Certificates snap-in screen opens.<br />

e. Click Computer Account and click Next. The Select Computer screen opens.<br />

15-25

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!