[RESOLVED] Assigning a certificate to a WAPT Administrator account

Share your tips or issues concerning the WAPT Console or WAPT Agent here
Forum Rules
Community Forum Rules
* English support on www.reddit.com/r/wapt
* French community support is available on this forum
* Please prefix the topic title with [RESOLVED] if it is resolved.
* Please do not edit a topic that is tagged [RESOLVED]. Open a new topic referencing the old one.
* Specify the installed WAPT version, full version, and build number (2.2.1.11957 / 2.2.2.12337 / etc.) as well as the Enterprise/Discovery edition.
* Versions 1.8.2 and earlier are no longer supported. The only questions accepted regarding version 1.8.2 are related to upgrading to a supported version (2.1, 2.2, etc.).
* Specify the server OS (Linux/Windows) and version (Debian Buster/Bullseye - CentOS 7 - Windows Server 2012/2016/2019).
* Specify the OS of the administration/package creation machine and the machine with the problematic agent, if applicable (Windows 7/10/11/Debian 11/etc.).
* Avoid asking multiple questions when opening a topic, otherwise it may be ignored. If there are multiple topics, open separate topics, preferably one after the other and not all at the same time (i.e., do not spam the forum).
* Include code snippets, screenshots, and other images directly in the post. Links to Pastebin, Bitly, and other third-party sites will be systematically removed.
* As with any community forum, support is provided voluntarily by members. If you require commercial support, you can contact Tranquil IT's sales department at 02.40.97.57.55
Locked
fobrian
Messages: 21
Registration: Sep 26, 2024 - 09:35

December 16, 2024 - 4:49 PM

Hello,
I have a question regarding assigning a certificate to an Administrator account created from the WAPT console.
Specifically, if I want to assign a certificate to a newly created user account, which certificate should I select?

Would it be, for example, the one located in the "C:\Program Files (x86)\wapt\ssl" directory of an already configured machine?

I tried to find information in the online documentation but only found this page: https://www.wapt.fr/fr/doc-2.5/wapt-sec ... e.html#acl

Thank you in advance for your help and patience, as I'm a recent beginner with WAPT.

Fred
User avatar
blemoigne
Messages: 178
Registration: July 17, 2020 - 11:29

December 17, 2024 - 11:07 AM

Hello Fred,
We recommend creating a unique certificate for each user for better traceability. Ideally, the steps should be as follows:
  • The new administrator creates their own named certificate (stored by default in c:\users\username\private).
  • It provides the public certificate (.crt) to an administrator already in place so that the latter can deploy it on the network via a certificate package.
  • Association of the certificate with the user in the ACLs window of the WAPT Console.
I hope I have answered all your questions!
Bertrand
fobrian
Messages: 21
Registration: Sep 26, 2024 - 09:35

December 18, 2024 - 3:08 PM

Hello Bertrand,

Thank you for your reply.
From what I understand, you do indeed need to log in once with the account to which you want to assign the certificate, and then create a new key from that window.

Fred
fobrian
Messages: 21
Registration: Sep 26, 2024 - 09:35

January 20, 2025 - 11:44

Hello,

I'd like to follow up on this post.
This might be a silly question, but once the new Administrator has created their own certificate, when associating the certificate with the Administrator from the "WAPT User and Rights Management" window, which certificate should be selected?
Is it the server's primary CA certificate that needs to be entered?

Picture

Because if I use this new user's personal ".crt" file, they don't have full rights to manage the workstations.

Thanks in advance.

Fred
fobrian
Messages: 21
Registration: Sep 26, 2024 - 09:35

January 27, 2025 - 12:15

Hello,

I finally found a solution.
Indeed, we needed to use the WAPT CA certificate located on our network share, and not the local one.

Fred
User avatar
dcardon
WAPT Expert
Messages: 1929
Registration: June 18, 2014 - 09:58
Location: Saint Sébastien sur Loire
Contact :

January 27, 2025 - 5:24 PM

Hi Frédéric,

thanks for the feedback, :-) I'm marking the topic as resolved.

Denis
Denis Cardon - Tranquil IT
Share your experiences on WAPT! Send us your blog and article URLs in the "Your Opinion of the forum, and we'll feature them on the WAPT
Locked