Q-See Remote Client Software V 4.0.1 Specifikace Strana 100

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 232
  • Tabulka s obsahem
  • ŘEŠENÍ PROBLÉMŮ
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 99
View Manager Administration Guide
100 VMware, Inc.
Bydefault,inViewConnectionServerwhenaclientvisitsasecurepagesuchas
View Administratortheyarepresentedwiththeselfsignedcertificateprovidedwith
theapplication.Byreadingtheservercertificatetheusercandecideiftheserverisa
trustedsource,andthenaccept(orreject)theconnection.
ThecertificatecanbesignedbyaCertificateAuthority(CA)—atrustedthirdpartywho
guaranteestheidentityofthecertificateanditscreator.
TocreateyourowncertificateforViewConnectionServerdooneofthefollowing:
Createaselfsignedcertificateforyoursystemusingthekeytoolutilityprovided
withtheJavaRuntimeEnvironment(JRE)instancethataccompaniesView
ConnectionServer.Selfsignedcertificatesareusergeneratedcertificatesthathave
notbeenofficiallyregisteredwithanytrustedCA,andarethereforenot
guaranteedtobeauthentic.
Createacertificateandthensendacertificatesigningrequest(CSR)thatcontains
yourcertificatedetailstoaCA.Afterconductingsomechecksonthecompanyor
individualmakingtheapplication,theCAsignstherequestandencryptsitwith
theirprivatekey.Thevalidcertificateisreturnedandisthen
insertedintoa
keystoreonViewConnectionServer.
ClientsconnectingtoViewConnectionServerarepresentedwithyourcertificate.Ifthe
certificateisselfsignedbutacceptedbytheuser,orsignedbyaCAthatistrustedby
theclientbrowser,theclientusesthepublickeycontainedwithinthe
certificateto
encryptthedataitsendstoViewConnectionServer.Typically ,thecertificatefortheCA
itselfisembeddedinthebrowserorislocatedinatrusteddatabasethatisaccessibleby
theclient.
Afteracceptingthecertificate,theclientrespondsbysendingasecretkey,whichis
encrypted
withtheserverspublickey.Thiskeyisusedtoencrypttrafficbetweenthe
clientandtheViewConnectionServerinstanceorsecurityserver.
Bydefault,ViewConnectionServerincludesaselfsignedSSLcertificatethatclients
canusetocreatesecuresessionswhentheyconnect.Thiscertificateisnot
trustedby
clientsanddoesnothavethecorrectnamefortheservice,butitdoesallowconnectivity.
N
OTEItisstronglyrecommendedthatyoucontinuetousethedefaultcertificate
providedwithViewConnectionServeruntilyouarereadytocreateyourown
certificateandgetitsignedbyaCA.
N
OTECertificatesareonlyrequiredforstandard,replica,orsecurityserversthat
receivedirectconnectionsfromtheirclients.Ifyouareusingasecurityserverasyour
clientfacingsystem,onlythisserverwillrequireacertificate.
Zobrazit stránku 99
1 2 ... 95 96 97 98 99 100 101 102 103 104 105 ... 231 232

Komentáře k této Příručce

Žádné komentáře