Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

From the authentication's point of view, device certificate authentication is basically Client Certificate Authentication. 

Client Certificate Authentication is a mutual certificate based authentication, where the client provides its Client Certificate to the Server to prove its identity. A client certificate is issued by a certificate authority (CA). DualShield has a built-in Root CA and it will use its built-in CA to issue device certificates.

To set up device certificate authentication in DualShield, we need to complete the steps below

Table of Contents

Import the Root CA

In the DualShield Admin Console, navigate to "Repository | Certificates | Certificate Authority" 

Click the "Import Root CA" button on the toolbar.

The Root CA should appear in the Certificate Authorities list as shown bellow:

Image Removed

Enable Client Authentication on the Root CA

Edit the Root CA

Image Removed

Image Removed

Enable the "Client Authentication" option.

Click "Save"

Add domains to the Root CA

In the Root CA's context menu, select "Domains"

Image Removed

Image Removed

Select the domains that will use the Root CA to issue device certificates.

Click "Save"

Update Trusted Store

After making changes to the CA certificates that are used for device or client certificate authentication, we need to update the Trusted Store.

Click the "Update Trusted Store" button on the toolbar

Image Removed

Image Removed

Restart DualShield service

Based Authentication (CBA). 

Include Page
Set up Certificate Based Authentication
Set up Certificate Based Authentication
Finally, we must restart the DualShield service.