Nortel 4050 用户指南

下载
页码 44
38 Chapter 2 Configuring TunnelGuard agent
NN47230-501 (324108-A)
 
2
Select Global User Profiles.
3
Select the profile to be deleted.
4
Click Delete Profile. A confirmation dialog box appears.
5
Click OK to delete the global user profile.
Configuring the TunnelGuard agent
You can configure the TunnelGuard agent default setting. You can also configure 
the single sign-on option. 
Certificate Management
TunnelGuard Agent manages its individual Java based Keystore that is installed 
as <installdir>/resources/keystore file. You can pre-populate this certificate store 
by Installing TunnelGuard Agent on a system and while attempting a User 
Session for SNAS.  TunnelGuard prompts you with Certificate warning and when 
"Always" option is selected, the certificate is added to the specified keystore.  
This keystore can be used as pre-populated keystore and deployed with 
TunnelGuard Installation, using MSI Customization.
Alternatively, you can take certificates that are already installed on your desktop 
in MSCAPI Certificate stores. To use MSCAPI Certificates, TunnelGuard Agent 
must be installed either with bundled JRE or with any JRE 6 or above.
If JRE 6 is used, TunnelGuard trusts all the certificates that are present in system’s 
ROOT Certificate store. If Trusted Certificate is not found either in TG Keystore 
or MSCAPI ROOT Truststore of machine (with JRE 6), System Profiles cannot 
login to SNAS. If trusted certificate is not found in any of the truststores, User 
Profiles prompts the user with a Certificate warning.  
If you choose to deploy TunnelGuard with an empty keystore using JRE 5 or 
below and without using MSI Customization, you must attempt a User Session to 
accept SNAS Certificate with "Always" Option, before attempting system session 
for the first time.