Last modified by Tobias Wintrich on 2024/06/03 15:08

Hide last authors
Tobias Wintrich 4.1 1 When using your own certificate infrastructure, it is necessary to make the root certificate known to the clients to ensure secure communication.
Tobias Wintrich 2.1 2
Tobias Wintrich 4.1 3 RangeeOS offers various options for deploying the certificate to a client or distributing it via a TCMS.
Tobias Wintrich 2.1 4
5 {{toc/}}
6
Tobias Wintrich 4.1 7 = Via the Thin Client's Kommbox =
Tobias Wintrich 2.1 8
Tobias Wintrich 4.1 9 Under {{status title="Tools"/}} -> {{status title="Certificates"/}}, you have the option "Install Certificates" to transfer a certificate to the client.
Tobias Wintrich 2.1 10
Tobias Wintrich 4.1 11 Here you can choose whether to install the certificates "Global" (distributable via TCMS) or only "Local" (usable only by this client).
Tobias Wintrich 2.1 12
13 [[image:01_zertifikate_installieren.png||height="316" width="600"]]
14
Tobias Wintrich 4.1 15 = Via a TCMS =
Tobias Wintrich 2.1 16
Tobias Wintrich 4.1 17 == Certificate as Part of the Group Configuration ==
Tobias Wintrich 2.1 18
Tobias Wintrich 4.1 19 The certificates installed as described under "Via the Thin Client's Kommbox" with the option //"Global"// (distributable via TCMS) can be transferred to other clients as part of the group configuration. To do this, pull a new group configuration from the respective client after installing the certificate.
Tobias Wintrich 2.1 20
Tobias Wintrich 4.1 21 == Distribute Certificates via a ZIP Archive ==
Tobias Wintrich 2.1 22
Tobias Wintrich 4.1 23 Alternatively, you can also distribute all certificates to your clients via a ZIP archive. To do this, proceed as follows:
Tobias Wintrich 2.1 24
Tobias Wintrich 4.1 25 === On the TCMS Side ===
Tobias Wintrich 2.1 26
Tobias Wintrich 4.1 27 Open the TCMS Kommbox (https://IP-hostname without /tcms) and navigate to {{status title="Tools"/}} -> {{status title="Certificates"/}} -> {{status title="Global Settings"/}}. At this point, you can upload an archive containing all the required certificates. The certificates must all be located in the root directory of the ZIP archive and be Base64 encoded (cert/pem).
Tobias Wintrich 2.1 28
Tobias Wintrich 4.1 29 === On the Thin Client Side ===
Tobias Wintrich 2.1 30
Tobias Wintrich 4.1 31 Navigate here as well to {{status title="Tools"/}} -> {{status title="Certificates"/}} -> {{status title="Global Settings"/}} and check the box "//Download the certificate archive from TCMS//". This will cause the certificate archive to be downloaded from TCMS again at each startup.