Monitoring HTTPS transactions
Response Time Monitoring monitors HTTP transactions by default. To monitor HTTPS transactions, Response Time Monitoring requires access to the SSL Certificates so that it can decrypt SSL traffic from your local web servers.
Before you begin
Identify the HTTPS web servers that you want to monitor,
including their IP addresses and configured ports. For example, 192.168.1.23,
port
443. For each HTTPS web server, check that Response Time Monitoring can read its ciphers. Response Time Monitoring supports the ciphers
supported by IBM Java, including the following ciphers. - RSA_WITH_RC4_40_MD5
- RSA_WITH_RC4_128_MD5
- RSA_WITH_RC4_128_SHA
- RSA_WITH_RC4_40_SHA
- RSA_WITH_DES40_CBC_SHA
- RSA_WITH_DESC_CBC_SHA
- RSA_WITH_3DES_EDE_CBC_SHA
- RSA_WITH_AES_128_CBC_SHA
- RSA_WITH_AES_256_CBC_SHA
- RSA_EXPORT1024_WITH_RC4_56_MD5
- RSA_EXPORT1024_WITH_RC2_CBC_56_MD5
- RSA_EXPORT1024_WITH_DES_CBC_SHA
- RSA_EXPORT1024_WITH_RC4_56_SHA
- TLS_RSA_WITH_AES_128_CBC_SHA256
- TLS_RSA_WITH_AES_256_CBC_SHA256
Restriction: Response Time Monitoring cannot decrypt traffic
that uses Diffie-Hellman key exchange.
Procedure
To enable HTTPS transaction monitoring, complete the following steps: