User's Manual 72 Document #: LTRT-27045
Mediant 1000B Gateway & E-SBC
5. Click Change; you are logged off the Web session and prompted to login in again with
your new login password.
6.7 Configuring Secured (HTTPS) Web
By default, the device allows remote management (client) through HTTP and HTTPS.
However, you can enforce secure Web access communication by configuring the device to
accept only HTTPS.
 To configure secure (HTTPS) Web access:
1. Open the Web Settings page (Setup menu > Administration tab > Web & CLI folder
> Web Settings).
2. Under the General group, configure the following:
3. From the 'Secured Web Connection (HTTPS)' drop-down list, select HTTPS Only.
4. To enable two-way authentication whereby both management client and server are
authenticated using X.509 certificates, from the 'Require Client Certificates for HTTPS
connection' drop-down list, select Enable.
5. In the 'HTTPS Cipher String' field, enter the cipher string for HTTPS (in OpenSSL
cipher list format).
6. Click Apply, and then reset the device with a save-to-flash for your settings to take
effect.
For more information on secure Web-based management including TLS certificates, see
''TLS for Remote Device Management'' on page 116.
6.8 Web Login Authentication using Smart Cards
You can enable Web login authentication using certificates from a third-party, common
access card (CAC) with user identification. When a user attempts to access the device
through the Web browser (HTTPS), the device retrieves the Web user’s login username
(and other information, if required) from the CAC. The user attempting to access the device
is only required to provide the login password. Typically, a TLS connection is established
between the CAC and the device’s Web interface, and a RADIUS server is implemented to
authenticate the password with the username. Therefore, this feature implements a two-
factor authentication - what the user has (i.e., the physical card) and what the user knows
(i.e., the login password).
This feature is enabled using the EnableMgmtTwoFactorAuthentication parameter.
Note: For specific integration requirements for implementing a third-party smart card
for Web login authentication, contact your AudioCodes representative.