05.08.2013 Views

OfficeScan 10 Administrator's Guide - Online Help Home - Trend Micro

OfficeScan 10 Administrator's Guide - Online Help Home - Trend Micro

OfficeScan 10 Administrator's Guide - Online Help Home - Trend Micro

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The CA Certificate<br />

Policy Server for Cisco NAC<br />

<strong>OfficeScan</strong> clients with CTA installations authenticate with the ACS server before<br />

communicating client security posture. Several methods are available for authentication<br />

(see the Cisco Secure ACS documentation for details). For example, you may already<br />

have enabled computer authentication for Cisco Secure ACS using Windows Active<br />

Directory, which you can configure to automatically produce an end user client<br />

certificate when adding a new computer in Active Directory. For instructions, see<br />

<strong>Micro</strong>soft Knowledge Base Article 313407, HOW TO: Create Automatic Certificate<br />

Requests with Group Policy in Windows.<br />

For users with their own Certificate Authority (CA) server, but whose end user clients<br />

do not yet have certificates, <strong>OfficeScan</strong> provides a mechanism to distribute a root<br />

certificate to <strong>OfficeScan</strong> clients. Distribute the certificate during <strong>OfficeScan</strong> installation<br />

or from the <strong>OfficeScan</strong> Web Console. <strong>OfficeScan</strong> distributes the certificate when it<br />

deploys the Cisco Trust Agent to clients (see Cisco Trust Agent Deployment on page <strong>10</strong>-26).<br />

Note: If you already acquired a certificate from a Certificate Authority or produced your<br />

own certificate and distributed it to end user clients, it is not necessary to do so again.<br />

Before distributing the certificate to clients, enroll the ACS server with the CA server<br />

and then prepare the certificate (see Cisco Secure ACS Server Enrolment on page <strong>10</strong>-24 for<br />

details).<br />

Policy Server System Requirements<br />

Before installing Policy Server, check if the computer meets the following requirements:<br />

Operating System<br />

• Windows 2000 Professional with Service Pack 4<br />

• Windows 2000 Server with Service Pack 4<br />

• Windows 2000 Advanced Server with Service Pack 4<br />

• Windows XP Professional with Service Pack 2 or later, 32-bit and 64-bit<br />

• Windows Server 2003 (Standard and Enterprise Editions) with Service Pack 2 or<br />

later, 32-bit and 64-bit<br />

• Windows Cluster Server 2000<br />

<strong>10</strong>-19

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!