CAA-WS, https to and from a Cloverleaf

Clovertech Forums Read Only Archives Cloverleaf Cloverleaf CAA-WS, https to and from a Cloverleaf

  • Creator
    Topic
  • #55152
    TorfinnK
    Participant

      Hello Clovertechers

      Running Cloverleaf 6.1.2 on Windows 2012 R2 and CAA-WS 2.0.

      We already has two interfaces, one client (sending to a ws) and one server (receiving), both using http and they Works fine.

      Now the customer wants to switch to https, and I

    Viewing 2 reply threads
    • Author
      Replies
      • #84347
        Russ Ross
        Participant

          I collect past clovertech URLs in case I need to leverage something from the past myself.

          Here are a couple of HTTP related URLs that talk a little about certificates even thought it is something I haven’t done myself.

          <a href="https://usspvlclovertch2.infor.com/viewtopic.php?t=5539&#8243; class=”bbcode_url”>https://usspvlclovertch2.infor.com/viewtopic.php?t=5539

          <a href="https://usspvlclovertch2.infor.com/viewtopic.php?t=7074&#8243; class=”bbcode_url”>https://usspvlclovertch2.infor.com/viewtopic.php?t=7074

          Russ Ross
          RussRoss318@gmail.com

        • #84348
          Elisha Gould
          Participant

            You’ll need to set up a keystore if one hasn’t been provided already.

            If you have a Root CA that you use within your organisation, then you may need to get a keystore set up for yourself, and your vendor (one for your server, one for the vendor).

            If the vendor is providing the certificates, then request that they provide you with a keystore or sign a Certificate Signing Request.

            The keystore will need at minimum:

            A signed private key alias

            A root ca certificate alias

            To set up in CAA-WS:

            For the server add a new engine that is TLS secured and fill in the Keystore information.

            For the client add a new http conduit that is TLS secured and fill in the Truststore information.

            If you have the keystore file with both the private and ca alias, the same keystore can be used for both.

            Set the permissions of the keystore so that only the hci user can access the file (or whichever user you use for your sites).

          • #84349
            Corrie Henry
            Participant

              TorfinnK,

              Did Elisha’s keystore recommendation work.  I also have a vendor who would like to send data to me via HTTPS.

          Viewing 2 reply threads
          • The forum ‘Cloverleaf’ is closed to new topics and replies.