Follow

How to: Set up Certificate Authentication for Web Admin and Aperture

Applies to:

Venafi Trust Protection Platform 14.1+

Summary:

Enable certificate authentication in Trust Protection Platform

  1. Log in to the Web Administration Console
  2. In the Platforms tree, make sure the root Platform object is highlighted and click the Authentication tab
  3. Check "Certificate Authentication"
  4. Click Apply.
  5. Log out of the Web Administration Console
  6. Launch the Web Administration Console. You should see the status message A valid certificate credential is required to log in.

Cert_Auth_enable_success.png

Configure IIS Manager to accept certificate authentication

  1. Open Administrative Tools.
  2. Click IIS Manager.
  3. Navigate to the top-level Venafi site.
  4. Click VEDAdmin
  5. Click SSL Settings.
  6. Select Require SSL and, under Client Certificates, select Require.
  7. Repeat steps 5 and 6 for Aperture

Cert_Auth_IIS_Config.png

Requirements for Authentication Certificate:

  • Must be issued by the same certificate authority that the VOC (Venafi Operational Certificate) is issued from. The VOC is the certificate used within IIS to enable HTTPS for Venafi web consoles and other web services.
  • The Common Name of the certificate must contain your username, it is what is used by Venafi to locate your account in the identity system (ex: Active Directory) and assign appropriate permissions to the user session.
  • Your certificate must have the key usage of "Client Authentication"

 

Was this article helpful?
0 out of 0 found this helpful

Comments