Configuring explicit-trust authentication with an XPU server
You can configure the authentication between an Enterprise Scanner agent and a
SiteProtector X-Press Update Server (XPU Server) to use either trust-all or
explicit-trust authentication.
Before you begin
To use explicit-trust authentication with an XPU Server,follow these steps:
vCopy the certificate file from the XPU Server to the agent as described in the
procedure later in this section.
vSpecify the fully qualified path of the certificate file in the CA Certificate box
when you configure the XPU Server.
About this task
The default trust level in the Proventia Manager is trust-all. In the SiteProtector
Console, the default trust level is left blank. The following table describes the
advantages and disadvantages of using each authentication method:
Table45. Advantages and disadvantages of each authentication method
Authentication method Advantages and Disadvantages
Trust-all Requiresno additional set up, but it is less
secure than explicit-trust authentication
Explicit-trust More secure than trust-all authentication;
but to use it, you must copy the certificate
file from the alternate XPU Server to the
agent.
Procedure
1. Locate the following certificate file on the SiteProtector X-Press Update Server:
server-rsa.crt The default location of this file for a stand-alone installation of
the SiteProtector X-Press Update server is the following path: C:\Program
Files\ISS\SiteProtector\X-Press Update Server\webserver\Apache2\conf\
ssl.crt\server-rsa.crt
2. Use a secure copy tool, such as SSH or Windows Secure Copy, to copy the
server-rsa.crt certificate file, and then paste it in the following directory on
the agent: /var/spool/leafcerts/server-rsa.crt
3. Rename the certificate file using the following format: IPaddress_port.pem
Note: The port number for the X-Press Update Server is 3994. Enterprise
Scanner recognizes the update server by the IP address.
150 Enterprise Scanner: User Guide