10.07.2015 Views

Provider-1/SiteManager-1 - Check Point

Provider-1/SiteManager-1 - Check Point

Provider-1/SiteManager-1 - Check Point

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Management ToolsMDS communication with CMAsEvery MDS Container communicates with the CMAs that it houses locally and securelythrough a protocol called SIC local. This type of authentication, SIC local, is managedby the <strong>Provider</strong>-1/SiteManger-1 environment and allows internal MDS communicationto be trusted.SIC is used for remote (not on the same host) communication, whereas SIC local isused for a host’s internal communication. SIC local communication does not make useof certificates.Trust between MDS to MDSThe primary MDS Manager, the first Manager created, has its own Internal CertificateAuthority. This ICA issues certificates to all other MDSs, so that trustedcommunication can be authenticated and secure between MDSs. All MDSs share oneInternal Certificate Authority.FIGURE 1-21 SIC between MDSsThe ICA creates certificates for all other MDSs, and for <strong>Provider</strong>-1/<strong>SiteManager</strong>-1administrators. Administrators also need to establish trusted communication with theMDSs.Authenticating the administratorAdministrators are authenticated to access the MDS via the MDG either by using a UserName and Password combination (which is considered only semi-secure) or by using acertificate issued by the MDS ICA (far more secure).Chapter 1 Introduction 37

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!