Create and Use an SSL on Goals Provide secure and encrypted 5250 data stream conversations with the server (including authentication) use a digital certificate we create with Digital Manager Show a client configuration example (looksoftware ) Benefits s secured access to 5250 data stream without VPN Delivers excellent response time will work for the server-side certificate for any 5250 application including Access for Windows Encrypts data, eliminates ability to sniff data stream Prevents undetected tampering with the data stream Learn about server/port/services interaction Save time or money and hassle in comparison Enterprise Security Interests Require SSL with telnet server from outside the LAN 4-1
4-2 PLEASE REGISTER TO GAIN ACCESS TO COMPLETE PRESENTATION! Create and Use an SSL on Assumptions Private user profiles and passwords will be issued Client software must support function to prompt user to indicate trust in server certificate issuer Prerequisites Part 1 Have administrator access (security officer) Within Have the HTTP Admin server started and working Have IBM Digital Manager installed License a cryptographic providers from IBM To enable, a moment of downtime will be required
4-3 PLEASE REGISTER TO GAIN ACCESS TO COMPLETE PRESENTATION! Create and Use an SSL on Prerequisites Part 2 For Enabling a static IP address mapped to your location Router, firewall or proxy server to enable access from internet WAN address to internal network LAN address with port restrictions by address
Create and Use an SSL on - Start - Go to IBM Navigator for i and Sign in Click on Network Servers TCP/IP Ensure HTTP Administration has a status of Started Otherwise, Right Click on it and Click Start 4-4
Create and Use an SSL on Run a browser session pointed to the HTTP Administration server address and Sign In Use Network System i Tasks Home Page 4-5
Create and Use an SSL on -OR- 1. Point your browser to http://ici270a:2001/httpadmin where ici270a is your server name or address Where 2001 is the HTTP admin server port 2. If the page is not found, eliminate anything beyond the 2001 (the standard port number) 3. If that doesn t work, the HTTP admin server has a problem or the admin port has been changed 4-6
Create and Use an SSL on Sign In Initial Page for HTTP Administration server Note: Most pictures are from i5/os running V5R4 Start Digital Manager 4-7
Create and Use an SSL on - Completion - Client-Side On the sign-on form, click on the little lock icon to see the certificate details is complete! 4-8