Authenticate the Inbound FTP Node Using Sterling External Authentication Server

Before you begin

Before you configure Secure Proxy to use Sterling External Authentication Server to authenticate an inbound node authentication, obtain the name of the Sterling External Authentication Server definition.

In addition, ensure that the following procedures have been performed:
  • The policy associated with the inbound node has enabled client authentication.
  • The public keys for Secure Proxy have been sent to the Sterling External Authentication Server and imported into the Sterling External Authentication Server key store.
  • The Sterling External Authentication Server server connection has been configured in Secure Proxy.

About this task

To authenticate certificate information or user information about the inbound node against information stored in an external database, you must configure Sterling External Authentication Server. After you configure Sterling External Authentication Server to enable certificate validation or user authentication, use this procedure to configure Secure Proxy to use the authentication method you defined in Sterling External Authentication Server.

To configure authentication of an inbound node using Sterling External Authentication Server:

Procedure

  1. From IBM Sterling Secure Proxy, select Configuration from the left hand-side navigation panel.
  2. Click Polices, then click View all Policies to display the list of created policies.
  3. Select the Policy you want to edit, click Edit icon.
  4. Click the Advanced tab.
  5. Configure one or more of the following options:
    • To validate the certificate presented by the inbound node against information defined in Sterling External Authentication Server, enable Certificate Authentication - External Authentication Certificate Validation and identify the name of the profile you defined in Sterling External Authentication Server in the Certificate Authentication - External Authentication Profile field.
    • To validate the user, enable Through External Authentication and identify the name of the profile defined in Sterling External Authentication Server in the External Authentication Profile field.
  6. Click Save.

Results

You can now associate this policy with the inbound node on which you want to perform user authentication using information stored in an LDAP server.