13.07.2015 Views

TRITON - Web Security Help, Version 7.7 - Websense

TRITON - Web Security Help, Version 7.7 - Websense

TRITON - Web Security Help, Version 7.7 - Websense

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

User IdentificationGenerating keys and certificates<strong>TRITON</strong> - <strong>Web</strong> <strong>Security</strong> <strong>Help</strong> | <strong>Web</strong> <strong>Security</strong> Solutions | <strong>Version</strong> <strong>7.7</strong>.xRelated topics: Manual authentication, page 297 Setting authentication rules for specific machines, page 299 Secure manual authentication, page 302 Activating secure manual authentication, page 304 Accepting the certificate within the client browser, page 305A certificate consists of a public key, used to encrypt data, and a private key, used todecipher data. Certificates are issued by a Certificate Authority (CA). You cangenerate a certificate from an internal certificate server, or obtain a client certificatefrom any third-party CA, such as VeriSign.The CA issuing the client certificate must be trusted by <strong>Web</strong>sense software. Typically,this is determined by a browser setting.For answers to common questions about private keys, CSRs, and certificates, seehttpd.apache.org/docs/2.2/ssl/ssl_faq.html#aboutcerts.To learn more about generating your own private key, CSR, and certificate, seewww.akadia.com/services/ssh_test_certificate.html.There are many tools that you can use to generate a self-signed certificate, includingthe OpenSSL toolkit (available from openssl.org).Regardless of the method you choose for generating the certificate, use the followinggeneral steps.1. Generate a private key (server.key).2. Generate a Certificate Signing Request (CSR) with the private key.ImportantWhen prompted for the CommonName, enter the IPaddress of the Filtering Server machine. If you skip thisstep, client browsers will display a security certificateerror.3. Use the CSR to create a self-signed certificate (server.crt).4. Save the server.crt and server.key files in a location that <strong>Web</strong>sense software canaccess, and where they can be read by Filtering Service.<strong>TRITON</strong> - <strong>Web</strong> <strong>Security</strong> <strong>Help</strong> 303

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!