Configure Certificate-Based Routing in Secure Proxy

About this task

Before you test certificate-based routing, you must create a certificate validation request in Sterling External Authentication Server that includes an attribute query definition called Routing Names. This attribute query definition is created to retrieve a routing name value using certificate attributes as search criteria. You must also configure a connection between Secure Proxy and Sterling External Authentication Server.

Refer to Configure Secure Proxy for Sterling External Authentication Server for instructions.

To configure certificate-based routing:

Procedure

  1. From IBM Sterling Secure Proxy, select Configuration from the left hand-side navigation panel.
  2. Click Adapters, then click View all Adapters to display the list of created Adapters.
  3. Choose the adapter you wish to edit, then click on the Edit icon.
  4. Select Certificate-based in the Routing Type field.
  5. Click Save.
  6. Navigate to the left-hand side navigation panel and click on Configuration > Netmap. Then, select the PeSIT Netmap tile to access the list of created PeSIT Netmaps. Finally, choose the specific PeSIT Netmap that contains the SNODE where the connections are routed.
  7. In the Netmap Nodes section, choose the node you wish to modify, then click on the Edit icon.
  8. Type the routing value to be returned from the LDAP server in the Routing Name field. The routing name must exactly match the routing value returned from the LDAP server. This routing name identifies the SNODE for routing the PNODE request.
  9. Click Save.
  10. Configure Secure Proxy to enable certificate authentication using Sterling External Authentication Server. Refer to Authenticate an Inbound Certificate or LogonID Using Sterling External Authentication Server.