Add SSL/TLS Support

This scenario builds on the basic PeSIT configuration by enabling security for the nodes you defined in the netmap.


Add SSL/TLS Support

Adding SSL/TLS support to the netmap for the nodes involves selecting the following options for the connections:
  • SSL or TLS Protocol
  • Cipher suites
  • Certificate stores and certificates

Add SSL/TLS support to the PNODE and the SNODE definitions. Set up SSL/TLS parameter files at both the SNODE and the PNODE servers. Obtain certificates for both sessions and check them into the certificate store. Then, test the connection.

Note: This procedure assumes you have checked in your certificates. Refer to Manage Certificates for SSL/TLS Transactions with Trading Partners for more information.

SSL/TLS Support Worksheet

Before you add SSL/TLS support to the connection information you created in the basic PeSIT configuration scenario, gather the information on the SSL/TLS Support Worksheet. You use this information as you configure the inbound and outbound nodes for SSL/TLS support.

Select the security setting and cipher suites to be used to secure the connection. To require that the certificate common name be validated in a certificate presented, enable this option and identify the common name value to check. Select the key/system certificate to use to validate the connection.

Configuration Manager

Feature

Value

Node Name

Name of the node to add security to, from the nodes you’ve already defined.

Use SSL

Enable this option to enable security checking

Enabled

Verify Common Name

Enable this option to enable common name checking. This is optional.

Enabled/Disabled

Certificate Common Name

Value of common name in certificate presented, if Common Name Checking is enabled.

Security Setting

Security protocol to use.

Draft comment: dkedward
Story #407766
  • SSLv3
  • SSLv3 with v2 Hello
  • SSLv3 or TLSv1
  • SSLv3, TLSv3, TLSv1.1, or TLSv1.2
  • TLSv1
  • TLSv1.1
  • TLSv1.2

Enable Client Authentication

Do you want to require the inbound connection to present its certificate for SSL or TLS client authentication?

Trust Store

Name of the store for the CA certificate or trusted root certificate

CA Certificates/Trusted Root

Name of CA certificate/trusted root

Key Store

Name of the store for the key or system certificate is stored

Key/System Certificate

Name of the Secure Proxy system certificate presented to the PeSIT server

Available Cipher Suites

Select the ciphers to enable by moving them from the Available Cipher Suites to the Selected Cipher Suites field