Dell Data Protection | Encryption Betriebsanweisung Seite 87

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 188
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 86
Enterprise Edition Administrator Guide 87
Configure Dell Key Server
This section explains how to configure components for use with Kerberos Authentication/Authorization when using a
DDP Enterprise Server. The DDP Enterprise Server - VE does not use the Key Server.
Dell Key Server is a Service that listens for
clients to connect on a socket. Once a client connects, a secure connection is
negotiated, authenticated, and encrypted using Kerberos APIs (if a secure connection cannot be negotiated, the client is
disconnected).
The Dell Key Server then checks with the Dell
Device Server to see if the user running the client is allowed to access keys.
This access is granted on the Remote Management Console via individual domains.
NOTE:
If Kerberos Authentication/Authorization is to be used, then the server that contains the Dell Key Server component will need to be
part of the affected domain.
NOTE: The DDP Enterprise Server - VE does not use the Dell Key Server, which affects how the Encryption client is uninstalled. Uninstallation
uses standard forensic key retrieval through the Dell Security Server instead of the Key Server’s Kerberos method. For available
parameters, see
Parameters
.
Windows Service Instructions
1
Navigate to the Windows Service panel (Start > Run... > services.msc > OK).
2
Right-click Dell Key Server and select
Properties
.
3
Go to the Log On tab and select the
This account:
option button.
4
In the This account: field, add the desired domain user. This domain user must have at least local Admin rights to the
Key Server folder (must be able to write to the Key Server config file, as well as the ability to write to the log.txt file).
5
Click
OK.
Restart the Service (leave the Windows Service panel open for further operation).
6
Navigate to <Key Server install dir> log.txt to verify that the Service started properly.
Key Server Config File Instructions
1
Navigate to <Key Server install dir>.
2
Open
Credant.KeyServer.exe.config
with a text editor.
3
Go to <add key="user" value="superadmin" /> and change the “superadmin” value to the name of the appropriate user
(you may also leave as “superadmin”).
The “superadmin” format can be any method that can authenticate to
the DDP Enterprise Server. The SAM account
name, UPN, or domain\username is acceptable. Any method that can authenticate to the DDP Enterprise Server is
acceptable because validation is required for that user account for authorization against Active Directory.
For example, in a multi-domain environment, only entering a SAM account name such as “jdoe” will likely will fail
because the DDP Enterpri
se Server will not be able to authenticate “jdoe” because it cannot find “jdoe”. In a
multi-domain environment, the UPN is recommended, although the domain\username format is acceptable.
In a single domain environment, the SAM account name is acceptable.
Seitenansicht 86
1 2 ... 82 83 84 85 86 87 88 89 90 91 92 ... 187 188

Kommentare zu diesen Handbüchern

Keine Kommentare