Add SSL or TLS Support

This scenario builds on the basic Connect:Direct® configuration by enabling security for the nodes you defined in the netmap.


Image shows SSL or TLS configured for the connection between the Connect:Direct PNODE and SSP engine. SSL or TLS is also configured for the connection between the SSP engine and Connect:Direct SNODE.

Adding SSL or TLS support to the netmap for the nodes involves selecting the following options for the connections:
  • SSL or TLS Protocol
  • Cipher suites
  • Certificate stores and certificates

Add SSL or TLS support to the PNODE and the SNODE definitions. Set up Connect:Direct Secure Plus parameter files at both the SNODE and the PNODE servers. Obtain certificates for both sessions and check them into the certificate store. Then, test the connection.

Note: This procedure assumes that you checked in your certificates. For more information, see About SSL/TLS certificates.

SSL and TLS Support worksheet

Before you add SSL or TLS support to the connection information you created in the basic Connect:Direct configuration scenario, gather the information in the SSL and TLS Support worksheet. You use this information as you configure the inbound and outbound nodes for SSL or TLS support.

Select the security setting and cipher suites to be used to secure the connection. To require that the certificate common name is validated in a certificate that is presented, enable this option and identify the common name value to check. Select the key or system certificate to use to validate the connection.

Configuration Manager

Feature

Value

Node Name

Name of the node to add security to

Select a node definition that you already defined

Security Setting

Secure Connection

Draft comment: dkedward
Story #407766
Enable Secure Connection to enable the use of an SSL or TLS protocol to ensure that data is secured as it is transmitted across a single socket.

SSL Configuration

SSL Configuration drop-down filed helps you choose the SSL