Securing the Connect:Direct connection by using the SSL or TLS protocol

The first step to strengthen security is to secure the communications channel. This procedure describes how to enable a SSL or TLS protocol for the Connect:Direct® connections to and from Secure Proxy in a netmap you created in the basic configuration.

About this task

To require that Secure Proxy perform common name checking, enable this option and identify the common name in the configuration.

Before you can configure this option, you must obtain the necessary certificates and place them in the Secure Proxy Cert Store. Refer to About SSL/TLS certificates for instructions.

To enable a SSL or TLS protocol:

Procedure

  1. From IBM Sterling Secure Proxy, select Configuration from the left hand-side navigation panel.
  2. Click Netmaps, then click View all Netmaps to display the list of created Netmaps.
  3. Choose the netmap you wish to edit, then click on the Edit icon.
  4. In the Netmap Nodes section, click on the three-dot menu and select Edit to modify a node.
  5. Click the Security tab, and then select Secure Connection checkbox to enable security.
    1. Enable Secure Connection to enable the use of an SSL or TLS protocol to ensure that data is secured as it is transmitted across a single socket.
    2. SSL Configuration drop-down filed helps you choose the SSL.
  6. Click Save.
  7. Establish a session that is initiated by a Connect:Direct PNODE to test the configuration.