Nortel 4050 用户指南
38 Chapter 2 Configuring TunnelGuard agent
NN47230-501 (324108-A)
2
Select Global User Profiles.
3
Select the profile to be deleted.
4
Click Delete Profile. A confirmation dialog box appears.
5
Click OK to delete the global user profile.
Configuring the TunnelGuard agent
You can configure the TunnelGuard agent default setting. You can also configure
the single sign-on option.
the single sign-on option.
Certificate Management
TunnelGuard Agent manages its individual Java based Keystore that is installed
as <installdir>/resources/keystore file. You can pre-populate this certificate store
by Installing TunnelGuard Agent on a system and while attempting a User
Session for SNAS. TunnelGuard prompts you with Certificate warning and when
"Always" option is selected, the certificate is added to the specified keystore.
This keystore can be used as pre-populated keystore and deployed with
TunnelGuard Installation, using MSI Customization.
as <installdir>/resources/keystore file. You can pre-populate this certificate store
by Installing TunnelGuard Agent on a system and while attempting a User
Session for SNAS. TunnelGuard prompts you with Certificate warning and when
"Always" option is selected, the certificate is added to the specified keystore.
This keystore can be used as pre-populated keystore and deployed with
TunnelGuard Installation, using MSI Customization.
Alternatively, you can take certificates that are already installed on your desktop
in MSCAPI Certificate stores. To use MSCAPI Certificates, TunnelGuard Agent
must be installed either with bundled JRE or with any JRE 6 or above.
in MSCAPI Certificate stores. To use MSCAPI Certificates, TunnelGuard Agent
must be installed either with bundled JRE or with any JRE 6 or above.
If JRE 6 is used, TunnelGuard trusts all the certificates that are present in system’s
ROOT Certificate store. If Trusted Certificate is not found either in TG Keystore
or MSCAPI ROOT Truststore of machine (with JRE 6), System Profiles cannot
login to SNAS. If trusted certificate is not found in any of the truststores, User
Profiles prompts the user with a Certificate warning.
ROOT Certificate store. If Trusted Certificate is not found either in TG Keystore
or MSCAPI ROOT Truststore of machine (with JRE 6), System Profiles cannot
login to SNAS. If trusted certificate is not found in any of the truststores, User
Profiles prompts the user with a Certificate warning.
If you choose to deploy TunnelGuard with an empty keystore using JRE 5 or
below and without using MSI Customization, you must attempt a User Session to
accept SNAS Certificate with "Always" Option, before attempting system session
for the first time.
below and without using MSI Customization, you must attempt a User Session to
accept SNAS Certificate with "Always" Option, before attempting system session
for the first time.