Strengthen Authentication for an HTTP Connection Using Sterling External Authentication Server

To provide a more advanced method of securing the inbound or the outbound connection, use Sterling External Authentication Server. Use Sterling External Authentication Server to authenticate certificate information or user credentials presented by the inbound node or to perform user ID and password mapping for the internal credentials. The following illustrates the security features enabled in this scenario.


Strengthen Authentication with SEAS

Authenticate an Inbound HTTP Certificate or User Using Sterling External Authentication Server

You can authenticate an inbound connection against information stored in an LDAP database by configuring Sterling External Authentication Server to define how the connection is authenticated. Following are some of the options Sterling External Authentication Server can perform:
  • Validate certificates, including dates and signatures
  • Verify the presence of X.509 v3 extensions
  • Enforce minimum key length requirements
  • Check certificates against certificate revocation lists (CRLs)
  • Perform LDAP queries

The Sterling External Authentication Server definition determines which options are enabled.

Manage Connection Requirements to the Outbound HTTP Server Using Sterling External Authentication Server

For a higher level of security when connecting to the outbound server, use information stored in an LDAP database to connect to the outbound server. To use information in an LDAP database, you configure Sterling External Authentication Server. Sterling External Authentication Server can map a user ID and password provided by an inbound connection to a user ID and password that is not exposed to the external node.

Authenticate an Inbound HTTP Certificate or User Using Sterling External Authentication Server Worksheet

Use the following worksheet to specify the information needed to authenticate a trading partner with information in Sterling External Authentication Server. Update the policy you created in the Basic HTTP Configuration for this scenario.

Configuration Manager Field

Information

Value

Certificate Authentication - External Authentication Certificate Validation

Will you validate the inbound certificate?

Yes or No

Certificate Authentication - External Authentication Profile

If yes, identify the Sterling External Authentication Server certificate validation definition.

User Authentication - Through External Authentication

Will you validate user information?

Yes or No

User Authentication - External Authentication Profile

If yes, identify the Sterling External Authentication Server user validation definition.