IBM Endpoint Manager, Version 9.2

Client Authentication

Client Authentication (introduced in version 9) extends the security model used by BigFix to encompass trusted client reports and private messages. This feature is not backward-compatible, and clients prior to version 9.0 will not be able to communicate with an authenticating relay or server.

Note: Some of the security options of the Client Authentication feature, can also be defined by setting the minimumSupportedClient and minimumSupportedRelay services as described in Additional administration commands for Windows system, or Running the BigFix Administration Tool for Linux systems.

The original security model has two central capabilities:

Client Authentication extends the security model to provide the mirror image of these two capabilities:

Communication using an authenticated relay is a two-way trusted and private communication channel that uses SSL to encrypt all communications. However, communication between a non-authenticating relay and its children is not encrypted unless it is an encrypted report or a mailboxed action or file.

This level of security is useful for many purposes. Your company may have security policies that require authenticating relays on your internet-facing nodes, in your DMZ, or any network connection that you do not totally trust. With authentication, you can prevent clients that haven’t yet joined your deployment from getting any information about the deployment.



Feedback