FTP Policy Configuration - Advanced

Use this tab to specify the type of user authentication to use for inbound access requests. For Certificate Authentication and User Authentication through Sterling External Authentication Server, you must have installed and configured Sterling External Authentication Server. You can also use this screen to map an incoming user ID and password to a different user ID and password to present to the internal server.

FTP Policy Configuration - Advanced fields are defined in the following table.

Field Name

Description

Certificate Authentication - External Authentication Certificate Validation

Turn on External Authentication Certificate Validation to validate information presented in certificates received from trading partners using Sterling External Authentication Server

Certificate Authentication - External Authentication Profile

External Authentication Profile identifies the name of the Certificate Validation Definition you defined in Sterling External Authentication Server. You must enable certificate validation before you can provide a profile.

User Authentication - Through External Authentication

Turn on User Authentication through External Authentication to send an incoming user ID and password to Sterling External Authentication Server for validation.

User Authentication - External Authentication Profile

If you enabled user authentication through External Authentication, identify the certificate authentication profile you defined in Sterling External Authentication Server in the External Authentication Profile field.

User Authentication - Through Local User Store

User Authentication Through Local User Store validates the user ID and password of the inbound node using information defined in the user store. You must add the user to the user store in order to successfully use this method.

User Mapping - Internal User ID

Determines what user ID and password is used to attach to the outbound node in the secure environment. User mapping options include:
  • Pass-through — Uses the user ID and password supplied by the inbound node to connect to the outbound node in the secure zone. To successfully connect to the outbound node, the user ID and password provided by the client must be valid at the target server.
  • From External Authentication — Uses a user ID and password from Sterling External Authentication Server to connect to the outbound node. To successfully connect using this option, the user ID and password must be defined in the LDAP database and must be valid at the target server.
  • From Netmap — Uses the user ID and password defined in the netmap to connect to the outbound node. To successfully connect using this option, define the user ID and password to use to connect to the target server in the outbound node definition.
  • SSO token from External Authentication—Uses a token from Sterling External Authentication Server to authenticate the user to the outbound node.