Inhaltsverzeichnis

Provide root CA for TightGate-Viewer centrally under Windows

If user authentication at TightGate-Pro is carried out via an Active Directory, the security certificate from TightGate-Pro must be trusted when logging in for the first time. This is necessary so that TightGate-Viewer can establish an encrypted connection to the TightGate-Pro server.

If you want to avoid the question about trusting the login appearing at the first login, you can store the root CA certificate centrally in the Windows certificate store. The following instructions describe the procedure.

Export Root CA

  1. Please access TightGate-Pro as administrator maint and select the menu item User administration > Create SSL key menu item.
  2. Select an existing USER and open the dialogue SSL key was created or updated for USER XYZ with OK to confirm.
  3. The following question Should the created certificates now be exported? with Yes to confirm.
  4. Now connect with an SFTP programme (e.g. WinSCP) to TightGate-Pro as user Administrator config. Under the directory /home/user/.transfer/config/certs/BENUTZER you will now find the file x509_ca.pem.
  5. Copy this file to the Windows computer into whose certificate store it is to be imported.
  6. Name the file x509_ca.pem to x509_ca.crt .

Import certificate file into the Windows certificate store

root-ca_1.jpg

root-ca_2.jpg

root-ca_3.jpg

root-ca_4.jpg

Removing the certificate file from the Windows certificate store

root-ca_5.jpg

root-ca_6.jpg

root-ca_7.jpg

root-ca_8.jpg

root-ca_9.jpg