Authenticate with Certificates in the Reflection X Advantage Store
Use this procedure to configure Reflection X Advantage Secure Shell sessions to authenticate users with certificates stored in the Reflection X Advantage store.
Note: The Secure Shell server administrator must configure the server to accept and validate user certificates. The procedure depends on the server. Refer to the Secure Shell server documentation for details.
Before you begin:
Obtain a personal certificate from a certificate-granting authority and copy it to a secure location on the computer running X Manager. Private keys and PKCS#12 packages should be placed in a folder that is readable only by the owner.
You can use:
- A certificate file and its associated private key. The two files must be in the same location and the certificate must have the same name as the key with a *.cer or *.crt file extension.
- A package file (*.p12, or *.pfx) that contains both the certificate and its associated private key.
You will also need to know the passphrase that has been used to protect the private key or certificate package file.
To authenticate with a certificate in the Reflection X Advantage store
- Launch X Manager or X Manager for Domains.
- From the Tools menu, select Secure Shell User Keys.
- Click Import.
- Browse to locate the private key file or certificate.
- For File passphrase enter the passphrase that currently protects the file. This is required to decrypt the file and import the key.
- For Key name enter a name for this certificate. This name shows up in the list of user keys and also appears in the prompt a user sees when this certificate is used to make a connection.
- Enter a value for Key passphrase. This can be the same as the original file passphrase or different.
Caution: To help ensure security, you should always specify a passphrase when you import a certificate. This passphrase protects the private key associated with the certificate. If you don't specify a passphrase, the private key is stored in unencrypted form in the Reflection X database, and anyone who gains access to the private key can authenticate using it. In standalone mode keys are stored on the same computer as X Manager. In domain mode all user keys are stored in the database on the domain controller and the administrator of that computer will be able to read these keys.
- Click Import.
The imported certificate is added to the User Keys list. As long as you leave Reflection X Advantage Store in the list under User Key Sources, Reflection X Advantage attempts to use certificates in this list when it connects to a host that supports certificate authentication.