Summary
Mutual TLS (mTLS) authentication with certificates configured on beacons and inventory device computers running the FlexNet inventory agent can be used help ensure a level of trust between beacons and inventory devices. This article describes how this may be configured using Client Certificate Mapping Authentication settings in IIS on a beacon.
There are two ways to configure Client Certificate Mapping Authentication:
- Using one-to-one client certificate mappings where inventory devices have a copy of the private key of the beacon's certificate.
- Using many-to-one client certificate mappings where the beacon only accepts connections from inventory devices that have certificates issued from a specific Certificate Authority.
This article is focused on the many-to-one type configuration, but the ideas described can be easily adapted to apply the one-to-one type configuration
Configuration overview
The purpose of this solution is to ensure that only authorized inventory devices can access a beacon. This setup is based on using Client Certificate Mapping Authentication that is configured in IIS.
The following diagram shows the high-level design of this configuration:
Key points illustrated in this diagram are:
- A certificate is configured in the IIS web site on the beacon.
- A client authentication certificate issued by the local certificate authority (CA) service is installed on each inventory device computer that the FlexNet inventory agent runs on.
- It is assumed that the beacon will be hosted in a dedicated AWS VPC network. The beacon should
have network access to any CA Certificate Revocation list (CRL) URLs that are specified in client certificates to protect against inventory devices with revoked or expired certificates from being able to connect to the beacon. - It is also assumed that an application firewall is implemented for additional network security. This is not a requirement, and not described further in this article.
Setup and configuration
The setup of this solution requires minimal changes in the IIS web site configuration on the beacon.
Prerequisites
This solution requires:
- The IIS Client Certificate Mapping Authentication role is installed on the beacon.
- Appropriate client certificates are deployed to inventory device computers.
- A Client and Server Authentication certificate is available for configuring on the beacon.
- The certificate issuer is configured in the Trusted Root Certification Authorities store on both the
beacon and all the Windows inventory device computers that are communicating with the beacon.
IIS configuration
The following steps illustrate how IIS may be set up on the beacon for this configuration.
- Install the Client and Server Authentication certificate in the Default Web Site Bindings:
- Configure the SSL Settings for the Default Web Site: check the Require SSL option, and the option to Require client certificates:
- Configure the IIS client certificate mapping properties:
- Set the manyToOneCertificateMappingsEnabled setting to True, and open the properties of the manyToOneMappings setting:
- Add Issuer as matching criteria to match client certificates that your beacon should accept. Additional Issuer and Subject criteria can be added if needed:
Related information
Additional information related to this topic can be found at the following locations:
- FlexNet Manager Suite documentation:
- FlexNet Manager Suite knowledge base:
- IIS documentation:
Related Articles
Using client certificates for mutual TLS (mTLS) authentication between internet-facing beacons and FlexNet inventory agents 87Number of Views Application usage metering using the FlexNet inventory agent 194Number of Views Secure your estate with HTTPS and TLS 145Number of Views Configure Client Certificate Authentication for FlexNet Inventory Agents 23Number of Views Common causes of high CPU usage by the ndtrack component of FlexNet inventory agent 407Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Revenera Assistant
Case id: 00001065
Activity: Status change: 2 hours ago