Safeguard for Privileged Passwords supports an SSL certificate store that is owned by the cluster. This allows you to assign any SSL certificate that you have previously uploaded or enrolled via CSR to any appliance in your clustered environment.
Follow the same steps to Unassign Certificate later.
An Appliance Administrator can upload a syslog client certificate so that Safeguard for Privileged Passwords can send authenticated messages to syslog servers that do not accept anonymous clients. For more information, see Syslog..
You can have only one syslog client certificate defined, which is used by all Safeguard for Privileged Passwords Appliances in the same cluster.
Instead of using the default syslog client certificate supplied, it is recommended you generate the Certificate Signing Request (CSR) using Create Certificate Signing Request (CSR). For more information, see Creating a syslog client Certificate Signing Request..
If you do use the default syslog client certificate, you are responsible for configuring the syslog server to accept the default certificate. For more information, see Installing a syslog client certificate..
Manage a Certificate Signing Request (CSR)
To define, generate, or manage a syslog client certificate, go to Syslog Client Certificate:
- web client: Navigate to Certificates > Syslog Client Certificate.
The following properties and controls are available to manage your syslog client certificate.
Table 32: Syslog Client Certificate: Properties
Refresh |
Click to get the latest information about the client certificate used. |
Subject |
Displays the client which is the name of the subject assigned to the certificate when it was requested. |
Thumbprint |
A unique hash value that identifies the certificate. |
Expiration Date |
The expiration date of the certificate. |
Add Certificate |
Click Add Certificate and select one of the following options to replace the default certificate with a new certificate:
|
Use Default |
Click Use Default to reset the certificate back to the default supplied by Safeguard for Privileged Passwords.
By default, the data is encrypted in transit but there is no authentication of the client/server. |
A certificate signing request (CSR) is submitted to a Certificate Authority (CA) to obtain a digitally signed certificate. When creating a CSR, you uniquely identify the user or entity that will use the requested certificate. Safeguard for Privileged Passwords allows you to upload or enroll a syslog client certificate using CSRs. Once uploaded or enrolled, the syslog client certificate is added to the syslog client certificate store allowing you to assign it to one or more Safeguard for Privileged Passwords Appliances.
To create a CSR for syslog
- Go to the following selection, based on your client:
- web client: Navigate to Certificates > Syslog Client Certificate.
- Click Add Certificate and select Create Certificate Signing Request (CSR).
- In the Certificate Signing Request dialog, enter the following information:
-
Subject (Distinguished Name): Enter the distinguished name of the person or entity to whom the certificate is being issued in the proper format like: cn=common name,ou=organizational unit,o=organization. Using the format example, cn=sam doe,ou=marketing,o=mycompany. Maximum length is 500 characters.
- Click Use Distinguished Name Creator to create the distinguished name based on your entries in Fully Qualified Domain Name (required), Department, Organization, City/Locality, State/County/Region, and Country.
-
Key Size: Select the bit length of the private key pair. The bit length determines the security level of the SSL certificate. A larger key size is more secure but encryption is slower.
-
Click OK to save your selections and enroll the certificate.
To install a syslog client certificate, the certificate must have at least the following:
To install a syslog client certificate
- Go to the following:
- web client: Navigate to Certificates > Syslog Client Certificate.
- Click Add Certificate and select one of the following:
- Install Certificate with a Private Key: To upload a PFX file that contains the certificate and the private key
- Install Certificate generate from CSR: To generate a CSR and have that signed by a trusted CA
- Browse to select the certificate file and complete the install.
- For Enter the private key passphrase:
- Enter the passphrase to import the certificate then click OK. Click to see the passphrase.
- If there is no passphrase, leave the field blank then click OK.
-
The Subject, Thumbprint, and Expiration date for the key you uploaded displays. You can select Use Default and respond to the confirmation dialog to return to the default, if desired.
- If you uploaded a certificate with a private key, you may upload the certificate's root CA to the list of trusted certificates. For more information, see Trusted CA Certificates..