Technological enhancements in B2B integration introduced by the new IT platform to manage the Commercial Process Nomination and Balancing



Similar documents
MAC Web Based VPN Connectivity Details and Instructions

Owner of the content within this article is Written by Marc Grote

Elenco Porte TCP/UDP

ing from The E2 Shop System address Server Name Server Port, Encryption Protocol, Encryption Type, SMTP User ID SMTP Password

Open Thunderbird. To set up an account in Thunderbird, from the Tools menu select Account Settings; choose account; then click Next.

USER GUIDE. Lightweight Directory Access Protocol (LDAP) Schoolwires Centricity

IBM Academic Initiative

Windows XP User guide for wired network v1.1

CTS2134 Introduction to Networking. Module Network Security

Windows Web Based VPN Connectivity Details & Instructions

Security IIS Service Lesson 6

Web Security (SSL) Tecniche di Sicurezza dei Sistemi 1

Configuring the Cisco ISA500 for Active Directory/LDAP and RADIUS Authentication

How to configure the Panda GateDefender Performa explicit proxy in a Local User Database or in a LDAP server

Certificates, Certification Authorities and Public-Key Infrastructures

Sync Security and Privacy Brief

Web Security: Encryption & Authentication

Corso: Configuring and Administering Windows 7 Codice PCSNET: MSW7-8 Cod. Vendor: Durata: 5

DEPLOYMENT GUIDE Version 1.1. Deploying the BIG-IP LTM v10 with Citrix Presentation Server 4.5

Elluminate Live! Access Guide. Page 1 of 7

File Transmission Methods Monday, July 14, 2014

Elastix SIP Firewall. Quick Installation Guide

Percorso Mcsa Managing and Mainting Windows 8

Update Instructions

Update Instructions

Chapter 10. Cloud Security Mechanisms

Linux Web Based VPN Connectivity Details and Instructions

How To Configure SSL VPN in Cyberoam

Royal Mail Business Integration Gateway Specification

VASCO Data Security. The Authentication Company. Richard Zoni Channel Manager Italy

Secure Messaging Server Console... 2

Lab - Observing DNS Resolution

WhatsUp Gold v16.2 MSP Edition Deployment Guide This guide provides information about installing and configuring WhatsUp Gold MSP Edition to central

SSL VPN. Virtual Private Networks based on Secure Socket Layer. Mario Baldi. Politecnico di Torino. Dipartimento di Automatica e Informatica

Advanced Configuration Administration Guide

Update Instructions

MS-55096: Securing Data on Microsoft SQL Server 2012

DEPLOYMENT OF I M INTOUCH (IIT) IN TYPICAL NETWORK ENVIRONMENTS. Single Computer running I m InTouch with a DSL or Cable Modem Internet Connection

NSi Mobile Installation Guide. Version 6.2

HTTP 1.1 Web Server and Client

Internet Technologies. World Wide Web (WWW) Proxy Server Network Address Translator (NAT)

CA Nimsoft Service Desk

D-LINK DPH-140S SIP PHONE INSTALLATION GUIDE

The PostBase Connectivity Wizard

How do I load balance FTP on NetScaler?

F-Secure Messaging Security Gateway. Deployment Guide

Internet Privacy Options

ProxySG TechBrief LDAP Authentication with the ProxySG

MS 10972A Administering the Web Server (IIS) Role of Windows Server

How To Configure L2TP VPN Connection for MAC OS X client

SCADA / Smart Grid Security Who is really in control of our Control Systems?

Lecture (02) Networking Model (TCP/IP) Networking Standard (OSI) (I)

How to Configure Active Directory based User Authentication

How To Establish Site-to-Site VPN Connection. using Preshared Key. Applicable Version: onwards. Overview. Scenario. Site A Configuration

Secure Socket Layer (SSL) Machines included: Contents 1: Basic Overview

How to set up the HotSpot module with SmartConnect. Panda GateDefender 5.0

Data Center Architecture

Come utilizzare il servizio di audioconferenza

Update Instructions

Network setup and troubleshooting

Elluminate Live! Access Guide. Page 1 of 7

External Authentication with Citrix Secure Gateway - Presentation server Authenticating Users Using SecurAccess Server by SecurEnvoy

10972-Administering the Web Server (IIS) Role of Windows Server

Cornerstones of Security

Application Notes for Configuring Yealink T-22 SIP Phones to interoperate with Avaya IP Office - Issue 1.0

White Paper How to Remotely Access Ethernet I/O Over the Internet

Secure Data Transfer

AD RMS Microsoft Federation Gateway Support Installation and Configuration Guide... 3 About this guide... 3

Why a Reverse Proxy with My Instant Communicator for mobiles??

Arcserve Cloud. Arcserve Cloud Getting Started Guide

M3-R3: INTERNET AND WEB DESIGN

22/11/ :08:30 Pag. 1/10

Two Factor Authentication in SonicOS

ISA Server Plugins Setup Guide

Sonian Getting Started Guide October 2008

STERLING SECURE PROXY. Raj Kumar Integration Management, Inc.

Network-Enabled Devices, AOS v.5.x.x. Content and Purpose of This Guide...1 User Management...2 Types of user accounts2

Remote Access to Embedded WEB by NAT Port Forwarding

Quick Start Guide. Cerberus FTP is distributed in Canada through C&C Software. Visit us today at

Is your data safe out there? -A white Paper on Online Security

Securing an IP SAN. Application Brief

How to Secure a Groove Manager Web Site

Central Administration QuickStart Guide

LDAP Authentication and Authorization

THINKTEL COMMUNICATIONS TALKSWITCH VS TALKSWITCH VS THINKTEL SIP TRUNK & DID

DEPLOYMENT GUIDE Version 2.1. Deploying F5 with Microsoft SharePoint 2010

Corso: Administering Microsoft SQL Server 2012 Databases Codice PCSNET: MSQ2-1 Cod. Vendor: Durata: 5

How To Lock A File In A Microsoft Microsoft System

Sophos UTM. Remote Access via PPTP. Configuring UTM and Client

IMF Tune Quarantine & Reporting Running SQL behind a Firewall. WinDeveloper Software Ltd.

Unified Threat Management

Transcription:

Technological enhancements in B2B integration introduced by the new IT platform to manage the Commercial Process Nomination and Balancing Detail of the activity and planning San Donato Milanese Aprile 2014 snamretegas

Agenda Objective and scope of the document B2B integration: Https protocol Certification B2B integration : Communication X12 Authentication Client/Server HTTPS and certificates 2

Objective and scope of the document Snam Rete Gas has identified a number of technological enhancements in B2B integrations, to manage the communications refer to the the Nomination process using X12/GISB protocol. Refer to the communication of 10 of March (to see pubblication on the istitutional web site) about: The summary of the possible impacts that these enhancements will have on Shippers (hereinafter UdT) The timing reference needed to ensure the proper exchange of information via the B2B X12 protocol. The objective of this document is to provide a detail than anticipated like indication for adapting the system, as well as the preliminary activities and its schedule of reference for using of new system by Shippers. 3

B2B integration: HTTPS Protocollo Certification In order to ensure an adeguate level of security for the B2B communication, in Logistica Gas System expected that the X12 feeds will be managed exclusively via HTTPS in both directions, with autenthication of the sender system (Basic Autentication) and cryption of sent message. The impacts to the Shippers can be distinguished by the type of exchanged feed with Snam Rete Gas, and in particular are classified as follows: B2B flow with UdT that implement only X12 850 (Nomination): In this case the Shippers to manage the communication to Snam Rete Gas using the HTTPS protocol with cryption message will have to share to Snam Rete Gas the pairs of Digital Certificates and Application Keys (UdT- SRG; for the Authentication part Snam Rete Gas will provvide the credentials) B2B flow with UdT that also implement messages X12 997 and/or 885 In this case the Shippers, refer to parameter for the message 850, will give to Snam Rete Gas an application URL that the Logistica Gas System will use for the communication back. 4

B2B integration: Logic Architeture HTTPS Communications Sistemi Snam Rete Gas X12.850 Internet X12.997 Integration Layer Logistica Gas X12.855 Legenda Security Layer Utente del Trasporto (UdT) Sistema UdT Comunicazioni HTTPS Certificato SRG Certificato Partner Messaggi X12 5

B2B integration: HTTPS Protocoll Certification Deadline Hereunder a detail of expected activities and their timing reference. Activity Description Planned Date List of contact point for testing activities Shipper will give to SRG the contacts to run the testing activities Within mid May 2014 Availability and Installation Digital certificates to load Pubblication of network parameters and access credentials on company web site Send network parameters and access credentials Pubblication of Test Book on company web site Running Test Connectivity Availability and Installation of Digital certificates as a prerequisite for run the connetivity test Udt vs SRG & SRG vs UdT SRG will provide the access credentials (IP address and port) for X12 communications In particolar, it is planned that: SRG send to all own digital cetificates, asking for the explicit confirmation to communicate via HTTPS In affermative case, SRG will provide some technical information (IP address, port, ) and the Shipper will give to SRG the informations requested (see the following requested activities) The Shippers that implement the system to receive the feed back (997, 855), they will have to give to SRG the parameters required for accessing (IP address, port, credentials) We have planned two testing case on the outcomes of messages 997 (ok; ko) like answer to 850 message sent by Shippers. Running test: After regularized the exchange of certificates for adapting the criteria of security, will run connectivity test to verify proper authentication of the Shipper, the correct sending of an nomination and the correct answers of Snam Rete Gas. Note.Prerequisite: to start testing you have to complete all previous tasks Within mid May 2014 Within mid May 2014 Within mid May 2014 Within end May 2014 Start: first week of June 2014 (elapsed planned 3 weeks) 6

B2B integration X12 Communication : Integration Test (1/2) To the Shipper that decide to use the X12 commuication on the new system, is planned a dedicated phase of Integrational Tests. Specifically, the approch to testing provides: Census and Registration of the Shippers that run the test; Identification a slot time for the test of each Shippers within the period dedicated to Integrational Test Using a collaboration tool useful for testing tracking/defect monitoring with related communication parameters /login credentials; Pubblication of the test book to Shippers It provides for the management of the common cases to all Shippers with indication of the reference database that the Shippers will use to send the messages ( example the list of meter to input the nomination value ) The list of meter is common to all Shippers, so no all meter will have capacity booking to Shipper 7

B2B integration X12 Comunication : Integration Test (2/2) Hereunder a detail of expected activities. Activities Description Planned Date Communication on the new code 855 on the company web site SRG will inform the Shippers the new encodings introduced to manage the output of the new semantic checks Census and Registration Census and Registration of the Shippers that run the test Communication on running test on the company web site SRG will inform the Shipper slot time for integration test For each Shipper the slot time is 3-5 day to test [range varies in function of type of implementated message by Shipper and then tested; specificaly Message 850the nomination rather than receiving response message (997, 855)] Note: for nework parameterrs and access credentials the Shippers have to refer to information to connectivity test Soon available Communication on the access to collaboration tool on the company web site Pubblication of the Test Book on the company web site SRG will inform the Shippers the parameters / access credentials to collaboration tool We have planned one-two testing case on semantic check in function of the two outcomes of messages (ok; ko) like answer to 850 message sent by Shippers. Run Integration Test Run Test between SRG and the Shippers 8

Authentication Client/Server HTTPS and certificates HTTPS HTTPS HTTP_BASIC_AUTH HTTPS WAN Internet F W LAN SNAM RETE GAS HTTPS: In telecomunicazioni e informatica HyperText Transfer Protocol over Secure Socket Layer (HTTPS) FIREWALL: è un componente passivo di difesa perimetrale di una rete informatica, che può anche svolgere funzioni di collegamento tra due o più tronconi di rete, garantendo dunque una protezione in termini di sicurezza informatica della rete stessa. HTTP_BASIC_AUTH HTTPS HTTP_BASIC_AUTH Logistica Gas HTTP_BASIC_AUTH HTTP_BASIC_AUTH: L'autenticazione BA non prevede protezione per le credenziali trasmesse. Esse vengono codificate con base 64 ma non criptate o crittografate con hash. È solitamente utilizzata in HTTPS.

Authenticaion Server/Server HTTPS and certificates (server answer to Shippers) UdT HTTP_BASIC_AUTH SNAM RETE GAS NLG HTTPS Integration FW Layer NLG Server key store Client trust store

Contacts Please contact Opcom.esercizio@snamretegas.it if you require any further clarification. To ensure the take-over of your request please write in the object field of mail : «LG Richieste di informazione LG Information request». Thanks for your attention Only for consultation - not binding 11