SSH Tectia

SSH Tectia®

Deployment Guide

SSH Communications Security Corp.

This software is protected by international copyright laws. All rights reserved. ssh® and Tectia® are registered trademarks of SSH Communications Security Corp in the United States and in certain other jurisdictions. The SSH and Tectia logos are trademarks of SSH Communications Security Corp and may be registered in certain jurisdictions. All other names and marks are property of their respective owners.

No part of this publication may be reproduced, published, stored in an electronic database, or transmitted, in any form or by any means, electronic, mechanical, recording, or otherwise, for any purpose, without the prior written permission of SSH Communications Security Corp.

THERE IS NO WARRANTY OF ANY KIND FOR THE ACCURACY OR USEFULNESS OF THIS INFORMATION EXCEPT AS REQUIRED BY APPLICABLE LAW OR EXPRESSLY AGREED IN WRITING.

For Open Source Software acknowledgements, see appendix Open Source Software License Acknowledgements in the Product Description.

30 June 2008


Table of Contents

1. About This Document
Documentation Conventions
Operating System Names
Directory Paths
Customer Support
2. Assessing the Environment
SSH Tectia Usage
SSH Tectia Product Feature Differences
IT Management Processes
Security Policies and Operational Guidelines
Network Topology
Managed Hosts
3. Planning SSH Tectia Manager Installation
Management Server
Management Database
Certification Authority
Distribution Server
Management Agent
Initial Configuration Block
4. Planning the Views
5. Admin Groups and Their Rights
Superusers
Operators
Configuration Administrators
Auditors
6. Planning the Deployment
Deploying SSH Tectia into an Unprotected Environment
Secure System Administration
Secure File Transfer
Secure Application Connectivity
Upgrading Legacy SSH Secure Shell to SSH Tectia
Upgrading SSH Tectia Client and Server from 4.x to 6.x
Deploying a Distributed Management Hierarchy
Managing a Distribution Server hierarchy
Adding a Distribution Server
High-Availability Setup for the Management Server
Prerequisites
Setting up the Primary Management Server
Setting up the Secondary Management Server
Failover steps
7. Planning Managed Host Upgrades
8. Managing PKI Authentication
Environment Options
Certificate Revocation Check
CA Hierarchy and Policy
PKI Deployment Example
Environment Description
Server Certificate Authentication
Server Host Certificate Enrollment
Maintenance
User Certificate Authentication
Index