SSL Configuration

Use this page to define secure connection requirements for an external trading partner. Refer to the field definitions in the following table.

Field Name Description
Name Name Identifies the name assigned to the SSL Configuration you created. Valid values are 1-150 alphanumeric characters with no spaces. Special characters allowed are period (.), dash (-), and underscore (_).
Description Description assigns a description to help you identify the SSL Configuration you create. Description can be up to 255 characters.
Verify Common Name (CD SSL) Click the Verify Common Name (CD SSL) checkbox. When transferring files between two Connect:Direct (CD) nodes using Sterling Secure Proxy (SSP) with a secure connection, the Common Name (CN) in the certificate of one CD node is verified by SSP to establish a secure connection with the other CD node. This is an optional field.
Security Setting Security Setting identifies the security protocols enabled for connections to this node. Options include the following security protocols:
  • SSLv3
  • SSLv3 with v2 Hello
  • SSLv3 or TLSv1
  • SSLv3, TLSv1, 1.1, or 1.2
  • TLSv1
  • TLSv1.1
  • TLSv1.2
Enable Client Authentication Enable Client Authentication on the inbound node connection to require that the Secure Proxy server authenticate the certificate presented by the inbound node connection.
Trust Store Location where trusted CA certificates are stored. CA certificates verify that a certificate received from a server is signed by a trusted source.
CA Certificates/Trusted Root CA Certificates/Trusted Root identifies the trusted certificate to use to authenticate the certificate presented by the client. You select a CA certificate or trusted root from the list of certificates stored in the trust store you selected in the Trust Store field. When a client presents a certificate to establish a secure connection, the trusted root certificate located at the server must match or be the entity who signed the certificate presented by the client during the SSL handshake.
Key Store Location where the key certificates you want to use are stored.
Key/System Certificate Certificate presented by Secure Proxy to the node to authenticate itself during the SSL handshake. Select the certificate to use for the node from the list that contains the key or system certificates stored in the key store selected in the Key Store field.
Available Cipher Suites

Available Cipher Suites is the list of ciphers that can be enabled to encrypt data that is transmitted during a secure SSL or TLS connection. Available cipher suites differ depending upon which version of SSL or TLS is selected. For more information about which ciphers are available for which versions of a security protocol, see Cipher Suites Supported.

Ensure that at least one cipher is enabled. To enable a cipher, highlight it and click . To enable multiple ciphers, highlight the ciphers to enable and click .

Selected Cipher Suites Selected Cipher Suites identifies the ciphers you have enabled to encrypt data during a secure SSL or TLS connection. A cipher suite is negotiated during a secure channel connection between a client and a server. Ciphers are negotiated based on their location in the Selected Ciphers list. To reorder a cipher in the list, highlight it and click Up or Down.
Clear Control Channel Enable Clear Control Channel to allow an inbound or outbound node to use an unencrypted control channel for commands after the SSL or TLS handshake is complete. The data channel for file transfers is still be encrypted.