Secure the PeSIT Connection Using the SSL or TLS Protocol

About this task

The first step to strengthen security is to secure the communications channel. This procedure describes how to enable an SSL or TLS protocol for the PeSIT connections to and from Secure Proxy in a netmap you created in the basic configuration. To require that Secure Proxy perform common name checking, enable this option and identify the common name in the configuration.

Before you can configure this option, you must obtain the necessary certificates and place them in the Secure Proxy Cert Store. Refer to

Draft comment: dkedward
Which topic does this link to?
Manage Certificates for SSL/TLS Transactions with Trading Partners for instructions.

To enable an SSL or TLS protocol:

Procedure

  1. Select Configuration from the menu bar.
  2. Expand the Netmaps tree and select a netmap to modify.
  3. Select a node to modify, and click Edit.
  4. Click the Security tab, and then click Use SSL to enable security.
  5. To enable common name checking:
    1. Click Verify Common Name.
    2. Type the certificate common name in the Certificate Common Name field.
  6. Select values for the following:
    • Security Setting
    • Key Store
    • Key/System Certificate
    • Available Ciphers
    • Selected Ciphers
  7. To enable client authentication:
    1. Click Enable Client Authentication.
    2. Select the Trust Store where the certificate you want to use is located.
    3. Select the CA Certificates/Trusted Root to use to authenticate the certificate presented by the inbound node.
    Note: Be sure to highlight the certificate to select. If only one certificate is displayed in the field, it is not selected until you highlight it.
  8. Click OK.
  9. Click Save.
  10. Establish a session initiated by a Sterling Connect:Express PNODE to test the configuration.