Configuring security settings for AS2 inbound exchange profile

Security settings for an AS2 inbound exchange profile include transport layer, integrity and nonrepudiation, and confidentiality settings.

Before you begin

Ensure that you have selected the required security policy.

About this task

This task provides information to configure transport layer, integrity and nonrepudiation, and confidentiality settings for an AS2 inbound exchange profile.

Procedure

  1. In the Security Settings section of Trigger: Receiver AS2 Messages from Trading Partners, click Configure.
  2. On the Configure Security Settings page, complete the following steps and click Save:
    Note: The fields that are displayed on the Configure Security Settings page are based on the configuration of the security policy that you have selected. Also, preselected or security settings are applied to the exchange profile. For example, if you have added a private/public key pair certificate alias and specified its usage as signing/signature verification, the certificate is applied by default.
    Field Description

    Transport layer security

    • Basic user authentication - If you have selected Require HTTP basic authentication in the security policy, you must add or select the user credentials that can be used for basic HTTP user authentication.

      When a message comes in, B2B Advanced Communications checks if the incoming message contains the correct user credentials.

    • HTTPS client authentication - If you have selected Require HTTPS client authentication in the security policy, you must select or add the public certificate alias of the trading partner organization that is used to authenticate the HTTPS client.

    Integrity and Non-repudiation

    • Signed messages - If you have selected Require signed messages in the security policy, you must select or add the trading partner organization public certificate alias that is used to verify the incoming message.
    • Signed MDN - If you have selected Require signed MDN in the security policy, you must select or add the owner organization private/public key pair certificate alias that is used to sign the MDN.

    Confidentiality

    Encrypted messages - If you have selected Require encrypted messages in the security policy, you must select or add the owner organization private/public key pair certificate alias that is used to decrypt the incoming message.