Authenticate a Connect:Direct Certificate or User Using Sterling External Authentication Server

About this task

To authenticate certificate information or user information about the Connect:Direct® node against information stored in an LDAP database, you must configure Sterling External Authentication Server. After you configure Sterling External Authentication Server to enable certificate or user authentication, complete this procedure to configure Secure Proxy to use the authentication method you defined.

Before you configure Secure Proxy to use Sterling External Authentication Server to authenticate a node connection, obtain the name of the Sterling External Authentication Server definition.

In addition, ensure that the following procedures have been performed:
  • The public keys for Secure Proxy have been sent to the Sterling External Authentication Server server and imported into the Sterling External Authentication Server keystore.
  • The Sterling External Authentication Server server connection has been configured in Secure Proxy.

To configure authentication of a Connect:Direct node using Sterling External Authentication Server:

Procedure

  1. From IBM Sterling Secure Proxy, select Configuration from the left hand-side navigation panel.
  2. Click Policies, then click View all Policies to display the list of created Policies.
  3. Choose the policy you wish to edit, then click on the Edit icon.
  4. On the Policy Configuration panel, click the Advanced tab.
  5. Configure one or more of the following options:
    • To validate the certificate presented by the node against information defined in Sterling External Authentication Server, enable Certificate Authentication: External Authentication Certificate Validation and enter the name of the profile you defined in Sterling External Authentication Server in the Certificate Authentication: External Authentication Profile field.
    • To enable user authentication through Sterling External Authentication Server, enable User Authentication: Through External Authentication and type the name of the definition you defined in Sterling External Authentication Server in the User Authentication: External Authentication Profile field.
  6. If you do not want to authenticate the user using information in the local user store, deselect the Through Local User Store option.
  7. Click Save.

Results

You can now associate this policy with a Connect:Direct node where you want to perform user authentication using information stored in an LDAP database.