Greetings,
Just reading up on Mutual Auth TLS for Remote Workers via an SBC and wanted to see if anyone has a link to a good application note or document they recommend that shows how to implement with SMgr/SBC. I already have TLS implemented with reverse proxies, but would like to take the extra step and lock it down more.
It seems like SCEP is the suggested method if dealing with a lot of users. But it seems with that method you provide all the end users a password to get their certificate? Would this be the same password or unique for each user? Can SMgr generate certificates for individual users for the PKCS12URL method? I know that may be more tedious for many users, but does that allow more control than SCEP (if its not a unique password per user)?
Just reading up on Mutual Auth TLS for Remote Workers via an SBC and wanted to see if anyone has a link to a good application note or document they recommend that shows how to implement with SMgr/SBC. I already have TLS implemented with reverse proxies, but would like to take the extra step and lock it down more.
It seems like SCEP is the suggested method if dealing with a lot of users. But it seems with that method you provide all the end users a password to get their certificate? Would this be the same password or unique for each user? Can SMgr generate certificates for individual users for the PKCS12URL method? I know that may be more tedious for many users, but does that allow more control than SCEP (if its not a unique password per user)?