03.03.2015 Views

eTrust Directory Administrator Guide - CA Technologies

eTrust Directory Administrator Guide - CA Technologies

eTrust Directory Administrator Guide - CA Technologies

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

DXconsole<br />

Testing the Secure Remote DXconsole Using TLSclient<br />

The TLSclient utility establishes an encrypted tunnel between the remote console<br />

client and the DSA. The steps to configure the DSA and TLSclient are as follows:<br />

1. Create the TLSclient configuration file on the client machine<br />

2. Configure the DSA for SSL connections to DXconsole on the server machine<br />

3. Start TLSclient on the client<br />

4. Start the DSA on the server<br />

5. Test the connection<br />

Create the TLSclient<br />

Configuration File<br />

To configure TLSclient, you will need to create the following file on the client<br />

machine:<br />

■<br />

■<br />

Windows: %DXHOME%\config\tlsclient\tlsclient.cfg<br />

UNIX: $DXHOME/config/tlsclient/tlsclient.cfg<br />

This implies that <strong>eTrust</strong> <strong>Directory</strong> is also installed on the client machine,<br />

although this may not be required. The only requirement should be that the<br />

environment variable DXHOME is set and the trusted root certificate is available.<br />

The format for tlsclient.cfg is:<br />

inPort outPort remoteAddress<br />

Where inPort is the port on the client machine that will be used for tunneling,<br />

outPort is the DXconsole remote-console-port on the server and remoteAddress<br />

is the hostname of the server running the DXconsole you wish to connect to.<br />

Here is an example for the sample DemoCorp DSA running on the server<br />

machine:<br />

19390 19395 hostname.ca.com<br />

Start TLSclient<br />

TLSclient can be installed to the system services using the command:<br />

tlsclient install -ca <br />

Here is an example for the DemoCorp DSA:<br />

tlsclient install democorp -ca config/ssld/trusted.pem<br />

You can then start the TLSclient instance with:<br />

tlsclient start <br />

For the DemoCorp DSA example, this would be:<br />

tlsclient start Democorp<br />

2–20 <strong>eTrust</strong> <strong>Directory</strong> <strong>Administrator</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!