Hand Held Products 7900 Series User Manual

Page 136

Advertising
background image

9 - 26

Dolphin® 7900 Series Mobile Computer User’s Guide

Server Tab

The Server identity tab defines the credentials the client uses to authenticate the server during TLS/TTLS/PEAP authentication
message exchange. The Client uses this information to verify that the Client is communicating with a trusted server.

Field

Description

Do not validate server
certificate chain

If this option is selected, the server certificate received during the TLS/TTLS/PEAP message
exchange is not validated.

Certificate issuer
must be

This is the certificate authority used during TLS/TTLS/PEAP message exchange. Any Trusted
CA
is the default selection and means that any certificate authority can be used during
authentication.

Both trusted intermediate certificate authorities and root authorities whose certificates exist in the
system store are available for selection in the drop-down list.

Allow intermediate
certificates

This option is selected by default. It enables a number of unspecified certificates to be in the
server certificate chain between the server certificate and the certificate authority indicated in the
Certificate issuer must be field. This allows the server certificate received during negotiation to
be issued directly by the certificate authority or by one of its intermediate certificate authorities.
If disabled, then the selected Certificate issuer must have directly issued the server certificate.

Server name must be

This is either the server name or the domain the server belongs to, depending on which option
is selected below the text field.

During authentication, this name will be compared to the server certificate’s Subject: CN field.

Must match exactly

When selected, the server name entered must match the server name found on the certificate
exactly.

Must contain domain
name

When selected, the server name field identifies a domain and the certificate must have a server
name belonging to this domain or to one of its sub-domains (e.g., zeelans.com, where the server
is blueberry.zeelans.com).

Advertising