If you download the SSL VPN client configuration from the self-service portal, you can enable SSO authentication on the SSL VPN server.
Note
Currently, the SSO authentication feature is in beta testing. If you need it, please submit a ticket.
Prerequisites
The Identity Provider has been applied for in CAM.
The VPN version is 4.0.
Enabling the feature while creating an SSL VPN server
1. Log in to the VPC console.
2. In the left directory, click VPN Connections > SSL VPN Server to enter the management page.
3. In the SSL server management page, click New.
4. In the pop-up New SSL VPN Server dialog box, select authentication method as Certificate Authentication + Identity Authentication and then select the EIAM application.
Parameter name | Parameter Description |
Protocol | Transmission protocol of the server. |
Port | Enter the SSL VPN server port used for data forwarding. |
Authentication Algorithm | Supported authentication algorithms: SHA1 and MD5. |
Encryption Algorithm | Supported encryption algorithms: AES-128-CBC, AES-192-CBC, and AES-256-CBC. |
Compressed | No. |
Authentication Method | Certificate verification: In this verification method, the SSL VPN server can be accessed through all SSL VPN client connections by default. Certificate Authentication + Identity Authentication: Use the CAM Identity Provider for SSO authentication. You need to select the created Identity Provider. |
Identity Provider | The current Identity Provider is Tencent Cloud Certificate Authority M. For more details, see the Identity Provider user guide. |
Access Control | SSL VPN Server access control switch. |
5. Access control can be enabled as needed. For details, see Enable Access Control.
Enabling the feature after creating an SSL VPN server
1. Log in to the VPC console.
2. In the left directory, click VPN Connections > SSL VPN Server to enter the management page.
3. In the SSL VPN Server management page, click the specific instance name.
4. On the instance details page, in the Basic Information tab, click Edit in the Server Configuration section.
5. Select Authentication Method as Certificate Authentication + Identity Authentication, choose a provider, and then click Save.