Authenticate with Certificates in a Local Directory
Use this procedure to configure Reflection X Advantage Secure Shell sessions to authenticate users with certificates stored locally (on the computer running X Manager or X Manager for Domains).
Note: The Secure Shell server administrator must configure the server to accept and validate user certificates. The procedure depends on the server. Refer to the Secure Shell server documentation for details.
Before you begin:
Obtain a personal certificate from a certificate-granting authority and copy it to a secure location on the computer running X Manager. Private keys and PKCS#12 packages should be placed in a folder that is readable only by the owner.
You can use:
- A certificate file and its associated private key. The two files must be in the same location and the certificate must have the same name as the key with a *.cer or *.crt file extension.
- A package file (*.p12, or *.pfx) that contains both the certificate and its associated private key.
You will also need to know the passphrase that has been used to protect the private key or certificate package file.
To authenticate with a certificate in a local directory
- Launch X Manager or X Manager for Domains.
- From the Tools menu, select Secure Shell User Keys.
- Next to User Key Sources click the plus sign (+) and select Add Local Directory.
- For Directory, specify the directory you want to use as for your store. Because this location contains a user's private keys it should be a location that is readable only by the user who authenticates with these keys.
- Click Import.
Note: Using the Import feature is recommended for adding keys to your directory. Reflection X Advantage sets correct permissions on imported keys and ensures that the key uses a supported file format.
- Browse to locate the private key file or certificate.
- For File passphrase enter the passphrase that currently protects the file. This is required to decrypt the file and import the key.
- For Key name enter a name for this certificate. This name shows up in the list of user keys and also appears in the prompt a user sees when this certificate is used to make a connection.
- Enter a value for Key passphrase. This can be the same as the original file passphrase or different.