|
|
| Sun One Portal Server, Secure Remote Access 6.0 Administration Guide |
Chapter 6 Working With Certificates
This chapter explains the authentication mechanisms provided by the Secure Remote Access along with the necessary configuration information.
This chapter covers the following topics:
Certificate Management
Generating a Self-signed SSL Certificate
Certificate Management
The Secure Remote Access provides certificate-based authentication for remote users. The Secure Remote Access uses Secure Sockets Layer (SSL) to enable secure communication. The SSL protocol enables secure communication between two machines.
Secure Remote Access also supports client authentication with Personal Digital Certificates (PDCs). PDCs are a mechanism to authenticate a user through SSL client authentication. With SSL client authentication, the SSL handshake ends at the gateway. The gateway extracts the user's PDC and passes it to the authenticated server. This server uses the PDC to authenticate the user.
You can either use a certificate that is issued by a Certificate Authority (CA), or generate and use self-signed certificates.
Certificate Files
When Sun ONE Portal Server, Secure Remote Access is installed, a self-signed SSL certificate is created and installed if you have chosen to install a self-signed certificate. If you have chosen not to install a self-signed certificate, only the certificate database is created. Certificate related files are located in /etc/opt/SUNWps/cert/default. This directory contains 5 files by default. The files and their descriptions are listed in Table 6-1.
Trust Attributes
The trust attributes of a certificate provide information about:
Whether the certificate is a regular server certificate (also called user certificate) as opposed to a root certificate
Whether the certificate (in the case of a root certificate) can be trusted as the issuer of a server or client certificate. There are three available trust categories for each certificate, expressed in this order: "SSL, email, object signing". For the gateway component, only the first category is useful. In each category position, zero or more trust attribute codes are used.
The attribute codes for the categories are separated by commas, and the entire set of attributes is enclosed by quotation marks. For example, the self-signed certificate generated and installed during the gateway installation is marked "u,u,u" which means it is a server certificate (user certificate) as opposed to a root CA certificate.
The possible attribute values and the meaning of each value are listed in Table 6-2.
Certificate Authorities (CAs)
Most well-known public CAs are already included in the certificate database. The following is the list of all the public CAs included by default, and their trust attributes. See Modifying the Trust Attributes of a Certificate for information on modifying the trust attributes of a public CA. Table 6-3 lists the most common Certificate Authorities with the trust attributes.
The certadmin Script
When the Sun ONE Portal Server, Secure Remote Access is installed, a self-signed SSL certificate is created and installed.
You can use the certadmin script to do additional certificate administration such as:
Generating a Self-signed SSL Certificate
Obtaining and Installing an SSL Certificate From a CA
Installing a Root CA Certificate
Modifying the Trust Attributes of a Certificate
gwcertutil
The certadmin script in InstallDir/SUNWps/bin/ is a script that wraps around the gwcertutil command for convenience. The certadmin script helps you carry out the conventional tasks related to certificate administration. For any additional functionality, use the gwcertutil command directly. For example, use gwcertutil to delete a certificate from the certificate database. The command gwcertutil -H lists usage.
Generating a Self-signed SSL Certificate
See Generating Self-signed Certificates in Chapter 4, Installing SSL Certificates in the Sun ONE Portal Server, Secure Remote Access 6.0 Installation Guide for details.
Obtaining and Installing an SSL Certificate From a CA
During the installation of the gateway component of the Secure Remote Access, a self-signed certificate is created and installed by default. At any point after installation, you can install SSL certificates signed by vendors who provide official certificate authority (CA) services, or by your corporate CA.
The three steps involved in this task are:
See Installing Certificates From a Certificate Authority in Chapter 4, Installing SSL Certificates in the Sun ONE Portal Server, Secure Remote Access 6.0 Installation Guide for details.
Listing Root CA Certificates
To View the List of Root CAs
where profilename is the name of the gateway instance.
The Certificate Administration menu is displayed.
Choose option 6 on the certificate administration menu.
List All Certificates
All certificates and their corresponding trust attributes can be viewed by using the certificate administration script.
To List all the Certificates
As root, run the certadmin script.
# InstallDir/SUNWps/bin/certadmin -n profilename
where profilename is the name of the gateway instance.
The Certificate Administration menu is displayed.
Choose option 7 on the certificate administration menu.
Modifying the Trust Attributes of a Certificate
One case in which the trust attributes of a certificate need to be modified is if client authentication is used with the gateway. An example of client authentication is PDC (Personal Digital Certificate). The CA that issues the PDCs must be trusted by the gateway, for example, the CA certificate should be marked "T" for SSL.
If the gateway component is set up to communicate with an HTTPS site that presents a self-signed certificate, allowing the gateway component to trust any unknown CAs can be a useful approach. However, for a serious deployment, this approach should be used with caution.
To Modify the Trust Attributes for a Certificate
As root, run the certadmin script.
# InstallDir/SUNWps/bin/certadmin -n profilename
where profilename is the name of the gateway instance.
The Certificate Administration menu is displayed.
Choose option 5 on the certificate administration menu.
Enter the name of the certificate. For example, Thawte Personal Freemail C.
Please enter the name of the certificate:
Thawte Personal Freemail CA
Enter the trust attribute for the certificate.
Please enter the trust attribute you want the certificate to have [CT,CT,CT]
The certificate trust attribute will be changed.
Previous Contents Index Next
Copyright 2002 Sun Microsystems, Inc. All rights reserved.
Last Updated September 26, 2002