Users must have certificate-based authentication configured before they can authenticate with a client certificate.
The client certificates used for certificate-based authentication are typically acquired with a smart card or similar device. Software bundled with the smart card hardware can extract the certificate file. This extracted certificate file is usually the file uploaded in this procedure.
For details about product features, usage, and best practices, click ? or Help.
Open the Edit User page.
Select Menu → User Management → Users.
Click New User, and specify a username.
Next to Authentication type, select Change authentication or credentials → Certificate-Based Authentication.
Use one of these methods to provide credentials.
Copy the DN field from the certificate file and paste it into the Personal Certificate Subject DN Field edit box.
Upload the signed certificate file: click Browse to navigate to and select the certificate file, then click OK.
Note
This certificate file was uploaded in the procedure, Configure MFS certificate-based authentication.
User certificates can be in PEM or DER format. The actual certificate format does not matter as long as the format is X.509 or PKCS12 compliant.
Click Save to save changes to the user's configuration.
The certificate information is verified. A warning appears if the certificate is invalid. If the certificate is vaild, the ePO - On-prem logon page appears. The user can choose a language and click Log On without entering a user name and password.