Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

push new certificate to client

We use SafeGuard Enterprise with authentication via RSA SID-800 Token with certificates on the token. If a user get a new token with a new certificate, generate by a company microsoft ca, the new certificate will be associated to the user in the SafeGuard Management Center. But when and how will this new certificate will be transfered to the client for usage at POA? Is it possible to push this? Which action can trigger this event?

Martin 

:26665


This thread was automatically locked due to age.
  • Hi me68,

    PKI certificates are not automatically pushed to the client / token. To bring the certificate onto the token, the certificate must be centrally assigned to the token or the user must be instructed to use the middleware of the token and import a certificate from the active directory / personal certificate store to his token - same doing as without SafeGuard Enterprise.

    After the certificate is on the token, token based certificate logon should work to POA and Windows.

    Hope that helps,

    Chris

    :26683
  • Hi Chris,

    sorry for bad explanation: i make a new certificate for a user on a new token or a replacement on the existing token via microsoft ca enrollment. Then i associate the new certificate to the user in the SafeGuard Managment Center (we use version 5.50.8), but if i use the new certificate on the client poa, the certificate is not known by poa. So i have to push it first to the client's poa. How can i do this?

    Martin

    :26701
  • I found it now: there was no policy defined for server communication: i defined now "server connection-intervall (minutes)" and now the client fetches the certificate.

    Martin :-)

    :26705