This section provides an example configuration of a server authentication using certificates in an SSH Tectia environment. The host certificates are enrolled for the SSH Tectia Server software, and the authentication settings configured for both the SSH Tectia Client and SSH Tectia ConnectSecure (or Connector in 4.x and 5.x) using SSH Tectia Manager.
The SSH Tectia Manager Internal CA provides the following services:
Enrollment service accesible only for the Management Agents
HTTP CRL service in port 80
CRL Distribution Point URL extension in the certificate
![]() | Note |
|---|---|
The administrator of SSH Tectia Manager is responsible for the identity establishment of the hosts. For example, the administrator needs to verify that the host information (host name, FQDN, IP address) is correct when selecting hosts for certificate enrollment. |
The SSH Tectia Manager Internal CA services are available after the initial configuration. The preconfigured Internal Root CA settings can be viewed and edited in Settings → PKI Settings → Internal CAs.
To enable the Internal PKI for certificate enrollment and authentication configurations in SSH Tectia Manager:
Under Configurations → Edit configurations → PKI → Enrollment settings, add the certificate enrollment settings (Figure 8.1).
In Enrollment PKI, select Internal Root CA.
Change the key type and length settings, if necessary.
Go to Configurations → Edit configurations → SSH Tectia G3 → Client → PKI.
To add the certificate authentication settings:
On the selected client's PKI tab, under CA list, click Add.
Select Use known CA certificate from and select Internal Root CA.
Upload the Internal Root CA certificate for server authentication (Figure 8.3).
Edit the configuration assignments:
Under Configurations → Assign configurations, edit the SSH Tectia G3 mappings.
Edit the G3 Client configuration for the intended configuration groups (for example, Server and Workstation).
Edit the Certificate enrollment configuration to refer to the internal CA for the intended groups (for example, Server).
Example configuration assignment is shown in Figure 8.4.