Using the Redirector :: Encryption

Configuring SSL Authentication

The Serial/IP Redirector can require the server to transmit an SSL certificate that the redirector can use to confirm the server's identity when the network connection to the server is being established.

In summary, the authentication process consists of the following steps, all of which must succeed for the SSL connection to continue:

  1. The redirector accesses the contents of the certificate supplied by the server.

  2. The redirector uses its Certificate Authority Keys to determine whether the certificate can be trusted.

  3. If the redirector has been configured with Validation Criteria, those settings are used to determine whether the connection will be allowed.

To configure SSL Authentication

In the Serial/IP Control Panel:

  1. Click Advanced to get the Advanced Settings window.

  2. Click the SSL Authentication tab.

  3. Select the check box Require Validated Certificate.

  4. To optionally specify validation criteria, select any check box and use the associated text field.

  5. In Certificate Authority Keys, select one of the two sources for the certificate authority keys. If using keys from a file, type the filename or select the file using Choose File.

  6. Click OK to make the changes effective.

Tips

The redirector has a built-in default set of certificate authorities.

A sample certificate authority file named "sampleca.pem" is provided in the Serial/IP installation folder. It is the certificate authority used to sign the sample certificate in "samplecert.pem".

 Notes

The %h and %a entries are typically only useful for matching the Common Name field in Validation Criteria.

These settings are global for the redirector.

  Related Topics

Encryption Requirements

Configuring SSL Encryption

Configuring the SSL Certificate

SSL Certificate Authorities