Specifications
Chapter 8 Authentication Services
• Click Use SSL in Trust All Mode to use SSL encryption for data transmission. All server certificates will be
trusted and automatically accepted by the DTX 5000-CTL Management Appliance for transmitting data. This
SSL method provides medium security and automatically sets the Port Number field to a default port number of
636.
This encryption mode is not recommended for wide area networks (WANs).
• Click Use SSL in Certificate-based Trust Mode to use SSL encryption for data transmission. The DTX 5000-CTL
Management Appliance will approve the server and then the certificate before transmitting data. This SSL
method provides maximum security and automatically sets the Port Number field to a default port number of 636.
9. Click Save to save your changes.
If you selected Use SSL in Certificate-based Trust Mode, the Certificates heading will appear in the side
navigation bar. Go to step 8.
If you selected Do Not Use SSL or Use SSL in Trust All Mode, go to step 15.
10. Click Certificates. The Authentication Service Certificate Management - LDAP window will open and list all servers
that belong to the domain. A status of Trusted indicates the certificate is trusted, based on the certificate policy;
Untrusted indicates the certificate cannot be trusted.
11. To register certificates, click the checkbox to the left of the server IP address(es). To select all server IP addresses
on the page, click the checkbox to the left of the IP Address heading.
12. Click Register to register the certificates. The Accept SSL Certificate window will appear.
13. Click Save to store the certificate values to the DTX Control database on the host.
The Certificate Management window will open if only one certificate was selected. If more than one certificate
was selected, each will appear in order in subsequent Accept SSL Certificate windows.
14. To unregister one or more certificates, check the checkbox to the left of the server IP address(es). To select all server
IP addresses on the page, click the checkbox to the left of the IP Address heading.
15. Click Unregister to unregister the certificates.
16. A confirmation message box will appear. Confirm or cancel the operation.
17. Click Close. The User Authentication Services window will open.
To change user schema settings for the LDAP external authentication service:
1. Click the Users tab.
2. Click Authentication Services in the top navigation bar. The User Authentication Services window will open.
3. Click the name of the LDAP service. The side navigation bar will change to include the name of the LDAP service at
the top and, below the name, the information you may define.
4. Click Schema in the side navigation bar. Users will automatically be selected and the Authentication Service User
Schema - LDAP window will open.
5. Type the Base distinguished name (DN) from which to begin searches. This is a required field unless the Directory
Service has been configured to allow anonymous search. Each Search DN value must be separated by a comma.
6. Type the key attribute. The default value is common name (cn).
7. Type the object class. The default value is person.
8. Type the full name attribute for the user. The default value is surname (sn).
9. Click Save and then click Close. The User Authentication Services dialog box will appear.
724-746-5500 | blackbox.com Page 66