Use the menu options in this section to allow or require certificate authentication in the Web UI.
To enable or disable the policy settings of the Web UI for certificate authentication:
Log in to the NDR as npadmin using the NDR IP address or FQDN. For example:
$ ssh npadmin@10.1.0.1or
$ ssh npadmin@exampleFQDNEnter privileged mode:
npadmin@ia> enableEnter the npadmin password. The password can be 5 to 24 characters long.
[sudo] password for npadmin: <password>Enter configuration mode:
npadmin@ia# configure systemEnter configuration CAC mode.
npadmin@ia(config)# authenticationIn the CAC/PIV configuration menu, select 1 to access the Authentication Mechanism menu.
Authentication Mechanisms: 1: PAM 2: LDAP 3: Radius 4: TACACS+ 5: Active Directory 6: PKI 7: PKI w/ LDAP 8: PKI w/ Active Directory C: Cancel changes and exitDepending on the external user management system you use, select a PKI option:
Enter
6if you will not configure LDAP or Active Directory with PKI for authorization.Enter
7to configure PKI with LDAP for authorization.Enter
8to configure PKI with AD for authorization.
In CAC/PIV configuration menu, select
2to configure your selected PKI authorization method.In the PKI configuration menu, select
1and enter the status. If a valid CA-signed certificate is not uploaded to the IA, you will not be able to enable CAC/PIV authentication.optional—Users can log in to the Web UI either using the user name and password provided by their administrator or using an optional X.509 certificate.required—Users must log in using a client X.509 certificate for user authentication.disabled—The appliance does not accept a client X.509 certificate. Users must log in with user name and password.
Select
Qto save your settings and exit the menu.