01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

5<br />

Authentication and access management<br />

Standard authentication<br />

SSL Client Certificate<br />

Settings specifying the SSL Client Certificate authentication method to authenticate users<br />

Note: These settings are provided if you have selected the SSL Client Certificate authentication method and<br />

configured the settings for the Authentication module accordingly. The settings name can vary.<br />

Authentication Method<br />

Settings for selecting an authentication method<br />

For more information, see User Database.<br />

Client Certificate Specific Parameters<br />

Settings for the SSL Client Certificate authentication method<br />

User name — Name of the user and other user-related information provided in the certificate that a<br />

client sends for authentication in SSL-secured communication<br />

This information is contained in the Subject section of the certificate. The client is required to send the<br />

certificate under this authentication method, which is also known as x.509 Authentication method.<br />

When the certificate is read on the appliance, user name information is checked according to what you<br />

specify here and assigned as a value to the Authentication.Username property.<br />

You can use the following variables to specify the user name information:<br />

• $O$ – Organization<br />

• $OU$ – Organizational unit<br />

• $U$ – Unit<br />

• $CN$ – Common name<br />

• $L$ – Location<br />

• $ST$ – State<br />

• $C$ – Country<br />

In addition to the variables, you can specify plain-text characters here, for example, backslashes to<br />

separate different pieces of information.<br />

Realm name — Name of the realm and other realm-related information provided in the certificate that<br />

a client sends for authentication in SSL-secured communication<br />

This information is contained in the Issuer section of the certificate.<br />

When the certificate is read on the appliance, realm information is checked according to what you<br />

specify here and assigned as a value to the Authentication.Realm property.<br />

You can specify the variables listed under User name here, as well as plain-text characters.<br />

Check extended key usage — When selected, the usage information belonging to the key for the<br />

certificate must contain Client Certificate as an entry<br />

Accept expired certificates for ... — Number of days during which a certificate is still accepted after<br />

it has expired<br />

Block certificates with unknown revocation status — When selected, certificates are not<br />

accepted on the appliance if their revocation status is not known<br />

Certificate Authorities — List of certificate authorities (CAs) that can issue a certificate used for<br />

authentication in SSL-secured communication<br />

The following table describes the list entries. For information on maintaining a list of this type, see<br />

Inline lists.<br />

136 <strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!