Exchange Reporter Plus SSL Configuration Guide



Similar documents
ADSelfService Plus: Guide to Install SSL Certificate. 1 P a g e

SSL Certificate Generation

Junio SSL WebLogic Oracle. Guía de Instalación. Junio, SSL WebLogic Oracle Guía de Instalación CONFIDENCIAL Página 1 de 19

SSL Configuration on Weblogic Oracle FLEXCUBE Universal Banking Release [August] [2014]

This document uses the following conventions for items that may need to be modified:

Creating an authorized SSL certificate

Configuring SSL in OBIEE 11g

Installing Digital Certificates for Server Authentication SSL on. BEA WebLogic 8.1

PowerChute TM Network Shutdown Security Features & Deployment

CA Nimsoft Unified Management Portal

Enable SSL in Go2Group SOAP Server

To install and configure SSL support on Tomcat 6, you need to follow these simple steps. For more information, read the rest of this HOW-TO.

Setting Up SSL on IIS6 for MEGA Advisor

Customizing SSL in CA WCC r11.3 This document contains guidelines for customizing SSL access to CA Workload Control Center (CA WCC) r11.3.

Chapter 1: How to Configure Certificate-Based Authentication

Version 9. Generating SSL Certificates for Progeny Web

DISTRIBUTED CONTENT SSL CONFIGURATION AND TROUBLESHOOTING GUIDE

Director and Certificate Authority Issuance

Configuring HTTPS support. Overview. Certificates

Configuring the JBoss Application Server for Secure Sockets Layer and Client-Certificate Authentication on SAS 9.3 Enterprise BI Server Web

SafeNet KMIP and Amazon S3 Integration Guide

Secure IIS Web Server with SSL

CHAPTER 7 SSL CONFIGURATION AND TESTING

RHEV 2.2: REST API INSTALLATION

Entrust Certificate Services. Java Code Signing. User Guide. Date of Issue: December Document issue: 2.0

KMIP installation Guide. DataSecure and KeySecure Version SafeNet, Inc

SSL CONFIGURATION GUIDE

1. If there is a temporary SSL certificate in your /ServerRoot/ssl/certs/ directory, move or delete it. 2. Run the following command:

IUCLID 5 Guidance and Support

How To Enable A Websphere To Communicate With Ssl On An Ipad From Aaya One X Portal On A Pc Or Macbook Or Ipad (For Acedo) On A Network With A Password Protected (

Exchange 2010 PKI Configuration Guide

Cisco Prime Central Managing Certificates

Configuring Secure Socket Layer and Client-Certificate Authentication on SAS 9.3 Enterprise BI Server Systems That Use Oracle WebLogic 10.

SafeNet KMIP and Google Cloud Storage Integration Guide

User Guide Generate Certificate Signing Request (CSR) & Installation of SSL Certificate

Creating the Certificate Request

How to Implement Transport Layer Security in PowerCenter Web Services

Enterprise Content Management System Monitor 5.1 Security Considerations Revision CENIT AG Brandner, Marc

Developers Integration Lab (DIL) Certificate Installation Instructions. Version 1.4

Configuring Secure Socket Layer (SSL) for use with BPM 7.5.x

WHITE PAPER Citrix Secure Gateway Startup Guide

Installing an SSL Certificate Provided by a Certificate Authority (CA) on the BlueSecure Controller (BSC)

How to Implement Two-Way SSL Authentication in a Web Service

Certificate technology on Pulse Secure Access

Certificate technology on Junos Pulse Secure Access

Securing Adobe connect Server and CQ Server

Installing an SSL Certificate Provided by a Certificate Authority (CA) on the vwlan Appliance

SolarWinds Technical Reference

Public Health Information Network Messaging System

C-Series How to configure SSL

Table of Contents INTRODUCTION... 2 SYSTEM REQUIREMENTS... 3 SERVICEDESK PLUS - MSP EDITIONS... 5 INSTALL SERVICEDESK PLUS - MSP...

Funambol Exchange Connector v6.5 Installation Guide

Scenarios for Setting Up SSL Certificates for View

Replacing Default vcenter Server 5.0 and ESXi Certificates

Certificates for computers, Web servers, and Web browser users

Copyright 2013 EMC Corporation. All Rights Reserved.

Configuring TLS Security for Cloudera Manager

Table of Contents INTRODUCTION... 2 SYSTEM REQUIREMENTS... 3 SERVICEDESK PLUS EDITIONS... 4 INSTALL SERVICEDESK PLUS... 5

LDAP User Guide PowerSchool Premier 5.1 Student Information System

X.509 Certificate Generator User Manual

Universal Content Management Version 10gR3. Security Providers Component Administration Guide

SSL Configuration on WebSphere Oracle FLEXCUBE Universal Banking Release [September] [2013] Part No. E

Lepide Active Directory Self Service. Configuration Guide. Follow the simple steps given in this document to start working with

Renewing an SSL Certificate Provided by a Certificate Authority (CA) on the vwlan Appliance

HTTPS Configuration for SAP Connector

VMware vrealize Operations for Horizon Security

SSO Plugin. Case study: Integrating with Ping Federate. J System Solutions. Version 4.0

TABLE OF CONTENTS I. INTRODUCTION... 1

VMware vrealize Operations for Horizon Security

Wildcard Certificates

Security Guide vcenter Operations Manager for Horizon View 1.5 TECHNICAL WHITE PAPER

User Guide Self Service Password Reset April 2012

MIGRATING TO AVALANCHE 5.0 WITH MS SQL SERVER

BlackBerry Enterprise Service 10. Version: Configuration Guide

SSL Configuration Best Practices for SAS Visual Analytics 7.1 Web Applications and SAS LASR Authorization Service

Browser-based Support Console

ECA IIS Instructions. January 2005

Service Manager 9.32: Generating SSL Profiles for an F5 HWLB

CA Business Intelligence

Marriott Enrollment Server for Web User Guide V1.4

1. Open the preferences screen by opening the Mail menu and selecting Preferences...

Best Practices for Disaster Recovery with Symantec Endpoint Protection

Microsoft OCS with IPC-R: SIP (M)TLS Trunking. directpacket Product Supplement

Enabling SSL and Client Certificates on the SAP J2EE Engine

CA Spectrum. Administrator Guide. Release 9.4

Working with Portecle to update / create a Java Keystore.

Protect your CollabNet TeamForge site

C O N F I G U R I N G O P E N L D A P F O R S S L / T L S C O M M U N I C A T I O N

Verify Needed Root Certificates Exist in Java Trust Store for Datawire JavaAPI

Application Notes for Microsoft Office Communicator Clients with Avaya Communication Manager Phones - Issue 1.1

(n)code Solutions CA A DIVISION OF GUJARAT NARMADA VALLEY FERTILIZERS COMPANY LIMITED P ROCEDURE F OR D OWNLOADING

DIGIPASS KEY series and smart card series for Juniper SSL VPN Authentication

EMC Data Protection Search

Installing BIRT Analytics 4.4

IIS, FTP Server and Windows

10gAS SSL / Certificate Based Authentication Configuration

QMX ios MDM Pre-Requisites and Installation Guide

Transcription:

Exchange Reporter Plus SSL Configuration Guide

Table of contents Necessity of a SSL guide 3 Exchange Reporter Plus Overview 3 Why is SSL certification needed? 3 Steps for enabling SSL 4 Certificate Request Process 4 Request for certificate from Microsoft Certificate Services 5 Associating the certificate with Exchange Reporter Plus 6 Glossary 7 2

Necessity of a SSL guide The purpose behind this document is to help you configure Exchange Reporter Plus for SSL certification. SSL certification protects all the sensitive information sent between users browser and Exchange Reporter Plus server by encrypting and transmitting the information through a secure channel. This document can help you with the following: Overview of Exchange Reporter Plus Need for SSL certification Steps to enable SSL certification Overview of Exchange Reporter Plus Exchange Reporter Plus is a web-based Exchange reporting solution with more than 100 reports on all the Exchange system components like Exchange Mailboxes Email Traffic Outlook Web Access Usage Distribution Lists Public Folders Exchange Information Stores Exchange Organization These reports collect all the vital data from data sources like Active Directory, Exchange Servers, Message Tracking logs, IIS logs and consolidate them into simple reports with graphs and charts. Why is SSL certification needed? Exchange Reporter Plus is a web-based software thus making it available even for on-the-fly access. The very purpose behind on-the-fly access is lost when there are chances of data transmitted between the browser and the server being compromised. SSL is the standard security technology on the web for establishing an encrypted secure channel for communication between the browsers and the servers. 3

Steps for enabling SSL To configure SSL in Exchange Reporter Plus, the following steps can be followed. 1. Login to Exchange Reporter Plus with admin credentials 2. Go to Admin -> Configurations -> Product Settings 3. Under Connection Settings, click Enable SSL Port [https] checkbox and Save the settings. 4. Restart Exchange Reporter Plus. Certificate Request Process Tomcat specific.keystore and.csr files need to be created before requesting certificates from a certifying authority. To create.keystore file 1. Open the command prompt 2. Browse to the <installation directory>\jre\bin folder and execute the below command keytool -genkey -alias tomcat -keypass <your key password> -keyalg RSA -validity 1000 -keystore <keystore_name>.keystore Note After executing the above query, you will be prompted with the following questions. a. Enter keystore password.( Try giving the password same as your key password and use plain characters.) b. What is your first and last name? (You can either provide the machine name hosting Exchange Reporter Plus application or FQDN here.) c. What is the name of your organizational unit? d. What is the name of your organization? e. What is the name of your City or Locality? f. What is the name of your State or Province? g. What is the two-letter country code for this unit? Finally acknowledge if the entered information is correct or not for the keystore file to be created. 4

To create.csr (Certificate Signing Request) file 1. Open the command prompt 2. Browse to the <installation directory>\jre\bin folder and execute the below command keytool -certreq -alias tomcat -keyalg RSA -keystore < keystore_name >.keystore -file <csr_name>.csr Note The.csr file is temporary and should be submitted to the Certifying Authority (CA) to receive CA-singed certificate files. Request for certificate from Microsoft Certificate Services (internal CA): The.csr file created is submitted to the certifying authority to receive a CA-singed certificate file. Follow the steps below to submit the file to the CA 1. Connect to Microsoft Certificate Services and click on Request a certificate link. 2. Click on Advanced Certificate Request 3. Submit a certificate request by using a base-64-encoded CMC or PKCS #10 file, or submit a renewal request by using a base-64-encoded PKCS #7 file 4. Open the.csr file using an editor, copy the content and paste it under Saved Request 5. Select Web Server as Certificate Template 6. Click on Submit button. 7. The certificate will be issued and click on Download certificate chain link to download PKCS #7 Certificates types. The downloaded file name should be defined as (certnew.p7b) Note: Copy and paste the certificate file under <installation directory>\jre\bin folder. 8. Click on the Home link on the top right hand side corner and click on Download a CA certificate, chain Certificate or CRL link to download the CA root certificate. 9. Click on Download CA certificate link and save the root certificate. The downloaded file name should be defined as (certnew.cer). Note: Copy and paste the certificate file under <installation directory>\jre\bin folder. 10. Browse to <installation directory>\jre\bin location using command prompt to import the internal CA certificate into.keystore file. 11. Execute the below provided query to import the certificate into.keystore file. Keytool import trustcacerts alias tomcat file certnew.p7b keystore <keystore_name >.keystore 5

12. Add your internal CA's root certificate to the list of trusted CAs in the Java cacerts file. 13. Execute the below provided query to add the root certificate into trusted CA list of Java file. keytool -import -alias <internal CA_name> -keystore..\lib\security\cacerts -file certnew.cer Note: Open the certnew.cer to get the internal CA name and provide the password as changeit when it is prompted. Associating the certificate with Exchange Reporter Plus This will configure the Exchange Reporter Plus server to use the keystore with your SSL certificate. To configure Exchange reporter Plus, follow the below steps. 1. Copy the.keystore from <installation directory>\jre\bin to <installation directory> \ conf folder. 2. Open server.xml file located at <installation directory> \ conf folder. Take a backup of the "server.xml" file before editing. 3. Replace the value of "keystorefile" to "./conf/<keystore_name>.keystore" at the last Connector tag (End of the page). 4. Replace the password for "keystorepass" to "password as given while creating keystore". 5. Save the server.xml file and close it. 6. Start Exchange Reporter Plus and connect to a browser. If you are able to view the Exchange Reporter Plus login console without any warning from the browser, you have successfully installed your SSL certificate in Exchange Reporter Plus! 6

Glossary Certifying Authority An organization that verifies the legitimacy and identity of a company or an individual and issues a digital certificate. CSR file Certificate Signing Request file initiated with a certificate provider during certificate generation process. The information of the applicant is contained in the file in an encrypted way. Keystore A key database file containing cryptographic entries. genkey A command used to generate a new keystore. alias Alias is a unique keystore entry. keypass A password to protect the private key of the generated key pair. storepass A password to protect the integrity of the keystore. keyalg Specifies the algorithm to be used to generate the key pair. Validity The number of days for which the certificate should be considered valid. 7