Inhaltsverzeichnis

User administration via user certificates

TightGate-Pro supports certificate-based login without entering user name and password for the client operating systems Windows and Linux. Certificate-based login requires that the users already exist in TightGate-Pro. This can be done by manual creation of users or by importing users . importing users.

The user defaults, such as file transfer or audio transmission, are taken from the administrator's system-wide user defaults of the administrator config .

Generate and distribute certificates

This is required

This is how it works

Preparatory measures

Generate certificates for existing users

Distribute certificates to clients

Hinweis

If the folder certs cannot be displayed in the lock of config , please check the settings of the TightGate lock.

Revoke certificates

If certificates of individual users are to be revoked so that logon is no longer possible, this can be done with the following instructions. If a user is deleted, all certificates issued for that user are also revoked. It is therefore not necessary to revoke certificates before deleting a user.

This is how it works

Achtung

Revoked certificates cannot be unblocked or reactivated. If necessary, new certificates must be generated and retrieved and distributed as specified above. In cluster systems, the revocation becomes effective after a waiting time of up to 10 minutes for logging in with the TightGate viewer and using the TightGate gateway. In the event of a certificate revocation, connections that have already been established remain in place until manual or automatic logout from the system. This applies equally to the TightGate viewer and the TightGate gateway.

Generate certificates in advance

As an alternative to generating certificates for existing user IDs, user certificates can also be generated in advance in any contingent. This allows users to log on to TightGate-Pro without a user account. This is generated automatically during the first login process, which reduces the administration effort.

Preparatory measures

This is how it works

Hinweise

  • The automatically generated user names create an identical user ID (user account) at TightGate-Pro the first time a user logs in with the generated certificate. This cannot be changed later.
  • No user ID (account) is created on TightGate-Pro as long as a certificate has only been generated but not yet used to log on to TightGate-Pro. The user administration of TightGate-Pro thus always contains only those identifiers that have actually already been used for logging in - regardless of the number of certificates generated in advance.

Remove/delete user

A user is removed by deleting him or her at TightGate-Pro in accordance with following these instructions.

Notes on deleting users with user certificates
The complete deletion of the user also recalls all user certificates (SSL certificates) with which the user has logged in. From now on, logging in with the certificates is no longer possible.