Last modified by Sabrina V. on 2026/07/23 07:34

Show last authors
1 {{aagon.priorisierung}}
2 10
3 {{/aagon.priorisierung}}
4
5 If a client is working from home and is therefore not on the local network, you can also issue a certificate to that client. Follow these steps:
6
7 If possible, the client should be physically connected to the local network at least once. You can then issue the certificate to the client in the Clients tab on the ribbon bar, in the Client certificates group, by selecting //Create// > //Automatic Distribution//. With this certificate, the client can then authenticate at the gateway and communicate with the ACMP Server even when outside the network.
8
9 If it is not possible to connect the client to the local network even once, you, as the administrator, can issue the certificate manually. To do so, proceed as follows:
10
11
12 **~1. Create a certificate**
13
14 Select the client in a Query and go to //Create// > //Manual Deployment// in the ribbon bar.
15
16 {{figure}}
17 [[image:63_System_UseCaseGateway_595.png||data-xwiki-image-style-alignment="center"]]
18
19 {{figureCaption}}
20 Button for Distribution Types
21 {{/figureCaption}}
22 {{/figure}}
23
24
25 In the wizard that opens, specify how long the certificate should be valid and select the location where the newly created certificate will be saved. Click //Run//.
26
27 A ZIP file is created containing the client certificate and the associated key. This ZIP file can be transferred via [[Launcher.exe>>doc:ACMP.610.ACMP-Solutions.Client-Management.Agenteninstallation.WebHome||anchor="HManualAgentInstallationviaLauncher.exe"]].
28
29
30
31 **2. Transfer Files to the Client**
32
33 This ZIP file must be transferred to the client via the most secure method possible, such as a USB drive or an encrypted email. The client user must unzip the file and copy both files to the %ProgramData%\Aagon\ACMP\Client directory.
34
35 {{figure}}
36 [[image:67_ACMP Gateway_Ordner_857.png||data-xwiki-image-style-alignment="center"]]
37
38 {{figureCaption}}
39 Certificates Stored in the Directory
40 {{/figureCaption}}
41 {{/figure}}
42
43
44
45
46 **3. Restart the system**
47
48 Afterward, either the computer or the ACMPClient service must be restarted. Once this is done, the administrator will see the distribution mode listed as “Deployed” in the client view.
49
50 The Gateway will now allow the connection from the authenticated and authorized client working from home. The manual certificate is also automatically renewed 30 days before it expires, just like the automatic certificate. This runtime is set by default and can be configured in Scheduled Server Tasks.
51
52 {{aagon.infobox}}
53 If a client does not contact the Gateway or the ACMP Server within 30 days BEFORE its certificate expires, a new certificate cannot be automatically issued to that client. In this case, the client will be locked out and rejected by the Gateway the next time it attempts to connect. In this case, you must issue a new certificate for this client for manual deployment and resend it to the client.
54 {{/aagon.infobox}}
© Aagon GmbH 2026
Besuchen Sie unsere aagon-Community