User guide

Odyssey Access Client Administration Guide
82 Using the Simple Method to Configure Trust
Use an intermediate CA or authentication server domain name to filter the
certificate chain when you install the certificate that specifies the issuer of the
trusted server certificates.
To add a trusted server:
1. Click Add in the Trusted Servers dialog to display the Add Trusted Servers
Entry dialog to begin the server configuration.
2. You can configure trust for any server that has been issued a specified signed
certificate, or you can specify one or more servers to be trusted using domain
names when those servers are issued a specified signed certificate:
To trust all servers that have a specified signed certificate, select Trust any
server with a valid certificate regardless of its name.
To specify servers by name, enter the identity of the trusted server in the
Server name must end with field.
3. Set the Server certificate must be issued by field to the name of the certificate
authority that must have directly or indirectly issued the server certificate. This
field is set automatically when you select a root or intermediate CA-issued
certificate. The name that appears in this field need not be the name of the
certificate authority that directly issued the server certificate. The server
certificate might be issued by any authority in the chain.
To set Server certificate must be issued by field:
a. Click Browse to display a list of certificates. The Select Certificate dialog
appears.
b. Select the required certificate from the list and click OK.
4. Click OK to close the Add Trusted Servers Entry dialog.
Server Identity
Each server has a unique identity. That name is usually located in the Subject CN
field of the server certificate.
A server identity might end with the name of a larger administrative domain to
which the server belongs. For example, the Acme company might have a domain
name, such as acme.com. The company might have multiple authentication servers
that are identified as auth1.acme.com, auth2.acme.com, and auth3.acme.com.
In this case, Acme might configure its server certificates with a common name
(acme.com) and enter the Server name must end with field with acme.com.
As in this example, by specifying the ending for a server name, you can configure
trust for all the servers in an organization with a single entry.
Removing a Trusted Server Entry
To remove an entry from the trusted servers list:
1. Select the entry from the Trusted Servers
dialog.