User guide

9: Services
SecureLinx Spider/SpiderDuo User Guide 83
Authentication Limitation
3. Do one of the following:
a. Click Save to save settings.
b. Click Reset to Defaults to restore system defaults.
c. Click Reset to restore original settings.
Certificate
The Spider uses the Secure Socket Layer (SSL) protocol for any encrypted network traffic
between itself and a connected client. During the connection establishment the Spider has to
expose its identity to a client using a cryptographic certificate. Upon leaving the factory this
certificate and the underlying secret key is the same for all Spiders and will not match the network
configuration where it is installed. The certificate’s underlying secret key is also used for securing
the SSL handshake. Leaving the default certificate unmodified is all right in most circumstances
and is necessary only if the network facility is vulnerable to man-in-the-middle attack.
It is possible to generate and install a new base64 x.509 certificate that is unique for a particular
Spider. The Spider is able to generate a new cryptographic key and the associated Certificate
Signing Request (CSR) that needs to be certified by a certification authority (CA).
To create and install an SSL certificate, perform the following steps.
1. Click Services > Certificate. The Certificate Signing Request page displays.
Table 9-8 Authentication Limitation
Field Description
Enable Screenshot
Access without
Authentication
Select this option when you need to access the snapshot image without
logging in to the Spider. If enabled, the screenshot can be read directly with
http(s)://<spiderIPaddress>/screenshot.jpg. One use of this
unauthenticated screenshot is to read it from a Google gadget
Enable Direct KVM
Console Access without
Authentication
Select this option to launch the Remote Console without authentication by
entering the Spider's IP address (http(s):/(Spider IP address) in the
browser's Address field or type javaws http(s):/(Spider IP
address in the command line. To launch Spider web access type
http(s):/(Spider IP address)/home in the browser’s Address field.