41
Step 17 Follow the prompts to configure the temporary SSL security certificate that secures the login
exchange between the Clean Access Server and untrusted (managed) clients (using field k.):
a. For the organization unit name, enter the group within your organization that is responsible
for the certificate (for example,
doc).
b. For the organization name, type the name of your organization or company for which you
would like to receive the certificate (for example,
Cisco Systems), and press Enter.
c. Type the name of the city or county in which your organization is legally located (for example,
San Jose), and press Enter.
d. Type the two-character state code in which the organization is located (for example,
CA or
NY), and press Enter.
e. Type the two-letter country code (for example,
US), and press Enter.
Step 18 Confirm values and press Enter to generate the SSL certificate, or type
n to restart:
You entered the following:
Domain: 10.201.240.10
Organization unit: doc
Organization name: Cisco Systems
City name: San Jose
State code: CA
Country code: US
Is this correct? (y/n)? [y] y
Note You must generate the temporary SSL certificate or you will not be able to access your CAS
as an end user.
Step 19 Specify whether or not you want the CAS to feature Pre-login Banner Support at the following
prompt.
Enable Prelogin Banner Support? (y/n)? [n]
For more information and an example of the Pre-login Banner feature, see the “Administering
the CAS” chapter of the Cisco NAC Appliance - Clean Access Server Installation and
Configuration Guide, Release 4.5(1).
Step 20 Configure the
root user password for the installed Linux operating system of the Clean Access
Server. The
root user account is used to access the system over a serial connection or through
SSH.
Cisco NAC Appliance supports using Strong Passwords for root user login. Passwords must
be at least 8 characters long and feature a combination of upper- and lower-case letters, digits,
and other characters. For example, the password
10-9=One does not satisfy the requirements
because it does not contain two characters from each category, but
1o-9=OnE is a valid
password. For more details, see the “Administering the CAM” chapter of the Cisco NAC
Appliance - Clean Access Manager Installation and Configuration Guide, Release 4.5(1).