Configure Certificate-Based Routing in Secure Proxy
About this task
Before you test certificate-based routing, you must create a certificate validation request in Sterling External Authentication Server that includes an attribute query definition called Routing Names. This attribute query definition is created to retrieve a routing name value using certificate attributes as search criteria. You must also configure a connection between Secure Proxy and Sterling External Authentication Server.
Refer to Configure Secure Proxy for Sterling External Authentication Server for instructions.
To configure certificate-based routing:
Procedure
- Select Configuration from the menu bar.
- Expand the Adapters tree and select the adapter you want to modify.
- Select Certificate-based in the Routing Type field.
- Click Save.
- Click the Netmap navigation panel, expand the Netmap tree, and select the PeSIT adapter that contains the SNODE where the connections are routed.
- Select the node to modify and click Edit.
- Type the routing value to be returned from the LDAP server in the Routing Name field. The routing name must exactly match the routing value returned from the LDAP server. This routing name identifies the SNODE for routing the PNODE request.
- Click OK.
- Click Save.
- Configure Secure Proxy to enable certificate authentication using Sterling External Authentication Server. Refer to Authenticate an Inbound Certificate or LogonID Using Sterling External Authentication Server.