Technical Notes |
|
This technical note provides an overview of Reflection PKI Services Manager, including how to obtain this component of Reflection for Secure IT, how it works, and an example of the basic steps to follow to configure PKI Services Manager in a Windows environment.
Reflection PKI Services Manager uses PKI to validate the authenticity of certificates presented by communicating parties. Using PKI Manager you can centrally configure and administer PKI functions, such as the following:
PKI Services Manager provides X.509 certificate validation services for the following products:
Note: Reflection for Secure IT Windows Client (all versions) does not use the PKI Services Manager for X.509 certificate validation; instead, the client performs its own certificate validation.
After installing and configuring PKI Services Manager, you should configure your installed Reflection for Secure IT product to connect to the PKI Services Manager and use the certificate validation services provided. For details about setting up client or server authentication, see the product user guides available from http://support.attachmate.com/manuals/sshdocs.html.
PKI Services Manager is included as a component of Reflection for Secure IT UNIX Server and Client and Reflection for Secure IT Windows Server, at no additional cost. Note: It is a separate download and installation.
The directions for obtaining the Reflection PKI Services Manager add-on vary depending on the type of customer: maintained or new customers, or evaluating customers.
Maintained customers are eligible to download PKI Services Manager from the Attachmate Download Library web site: https://download.attachmate.com/Upgrades/.
New Volume Purchase Account customers can use link(s) in the e-mail message sent to the order "ship to" contact to download PKI Services Manager files.
The PKI Services Manager file downloads for various platforms are listed in the Download Library under the heading, "Supplemental File Utility or Add-On," which appears below the "Current Product Release" and "Service Pack or Patch" headings.
You will be prompted to login and accept the Software License Agreement before you can select and download the PKI Services Manager file. For more information on using the Download Library web site, see Technical Note 0200.
PKI Services Manager is available to evaluate when you request an evaluation copy of the following Reflection for Secure IT products from the Attachmate web site (http://www.attachmate.com/Evals/rsit/rsit-eval.htm):
You will be prompted to fill out a form and then will receive e-mail with instructions about downloading the evaluation software.
The PKI Services Manager file downloads are intermixed in the file listing of Reflection for Secure IT product downloads, both of which are organized by available platforms under the "Description" heading. The PKI Services Manager file downloads include "PKI Add-On" at the end of the platform description.
If you downloaded the Reflection for Secure IT evaluation software, you must navigate back to the file listing page to obtain the PKI Add-On. Alternatively, you can click the link in the original e-mail to return to the file listing page.
The following diagrams show how PKI Services Manager validates certificates used for authentication. The first example shows how an SSH Windows or UNIX server uses PKI Services Manager to validate a certificate used for client authentication, and the second example shows how an SSH UNIX client performs the same task during host certificate authentication. Refer to the steps below each diagram for an explanation of the process in each environment.
Figure 1: Validate client authentication certificate process diagram.
Figure 2: Validate host authentication certificate process diagram.
Configuring PKI is a multi-step process:
Note: The example in this technical note provides basic steps to configure PKI. Use this information as a starting place to understand how to configure PKI for your environment.
The following steps use a Windows PKI Services Manager and a Local Store for the CA Certificate Trust Anchor and CRL checking. When configuring the PKI Services Manager, you must be logged in as an administrator.
C:\Documents and Settings\All Users\Application Data\Attachmate\ReflectionPKI\Local-storeor
C:\Users\All Users\Attachmate\ReflectionPKI\Local-store
Figure 3: Identifying URL paths for the CRL Distribution Points.
Figure 4: Sample path to Local Store.
Mapping User Certificates:
Select the “Apply this rule only to this server” check box and enter the server name, for example, winserv1. (Do not use the server’s DNS host name).
Note: This step is required if you are using Windows local accounts. You may skip this step if you are using Windows domain accounts.
<domain name1>\<username1>,<domain name1>\<username2>- Enable "Allow authentication if the following condition is met."
- Select "Subject Common Name" from the first drop-down list.
- Select "Contains" from the second drop-down list.
- In the third field, enter a value found for Subject when viewing details of the client certificate.
- Click OK. The rule will display as follows:
User-address=winserv1{<domain name1>\<username1>,<domain name1>\<username2>}Subject Contains <Value>.Note: The status bar will display the rule as you build it.
View Full Size
Figure 5: Sample mapped user certificate.
Mapping Server Certificates:
ServerIPAddress, ServerName- Enable "Allow authentication if the following condition is met."
- Select "Subject Common Name" from the first drop-down list.
- Select "Contains" from the second drop-down list.
- In the third field, enter a value found for Subject when viewing details of the client certificate.
- Click OK. The rule will display as follows:
host{<ServerIPAddress>, <ServerName>} Subject.CN Equals <Value>.Figure 6: Sample mapped server certificate.
winpki startThe following steps use the Reflection for Secure IT Windows Server as an example.
Figure 7: Sample PKI server configuration.
For instructions about configuring the Reflection for Secure IT clients (either Windows or UNIX) to authenticate using certificates, see the appropriate product documentation:
For the Reflection for Secure IT Windows Client, see http://support.attachmate.com/manuals/rsit_win_client.html.
For the Reflection for Secure IT UNIX Client, see http://support.attachmate.com/manuals/rsit_unix.html.
PKI Services Manager User Guide:
Reflection for Secure IT Windows Server Documentation:
Reflection for Secure IT Windows Client Documentation:
Reflection for Secure IT UNIX Client and Server Documentation:
Reflection PKI Services Manager Supported Platforms: Technical Note 2427