How To Enable A Websphere To Communicate With Ssl On An Ipad From Aaya One X Portal 1.1.3 On A Pc Or Macbook Or Ipad (For Acedo) On A Network With A Password Protected (

Similar documents
S/MIME on Good for Enterprise MS Online Certificate Status Protocol. Installation and Configuration Notes. Updated: October 08, 2014

Setting Up SSL on IIS6 for MEGA Advisor

Outlook Web Access Guide to Installing Root Certificates, Generating CSR and Installing SSL Certificate

Wavecrest Certificate

etoken Enterprise For: SSL SSL with etoken

Step-by-step installation guide for monitoring untrusted servers using Operations Manager ( Part 3 of 3)

DIGIPASS KEY series and smart card series for Juniper SSL VPN Authentication

IIS, FTP Server and Windows

NSi Mobile Installation Guide. Version 6.2

How to Enable LDAP Directory Services Authentication to Microsoft Active Directory in the HP cclass Onboard Administrator

How To Take Advantage Of Active Directory Support In Groupwise 2014

Certificate Request Generation and Certificate Installation Instructions for IIS 5 April 14, 2006

ECA IIS Instructions. January 2005

DMZ Server monitoring with

SQL Server 2008 and SSL Secure Connection

Configuring Secure Socket Layer (SSL) for use with BPM 7.5.x

ADFS Integration Guidelines

Customer Tips. Xerox Network Scanning HTTP/HTTPS Configuration using Microsoft IIS. for the user. Purpose. Background

Dell SupportAssist Version 2.0 for Dell OpenManage Essentials Quick Start Guide

SETUP SSL IN SHAREPOINT 2013 (USING SELF-SIGNED CERTIFICATE)

CA NetQoS Performance Center

HTTP communication between Symantec Enterprise Vault and Clearwell E- Discovery

Tenrox. Single Sign-On (SSO) Setup Guide. January, Tenrox. All rights reserved.

HTTP Server Setup for McAfee Endpoint Encryption (Formerly SafeBoot) Table of Contents

WHITE PAPER Citrix Secure Gateway Startup Guide

Install the Production Treasury Root Certificate (Vista / Win 7)

Verify LDAP over SSL/TLS (LDAPS) and CA Certificate Using Ldp.exe

Step-by-step installation guide for monitoring untrusted servers using Operations Manager (Part 1 of 3)

USING SSL/TLS WITH TERMINAL EMULATION

Microsoft OCS with IPC-R: SIP (M)TLS Trunking. directpacket Product Supplement

Generating an Apple Push Notification Service Certificate for use with GO!Enterprise MDM. This guide provides information on...

Deploying Personal Virtual Desktops by Using RemoteApp and Desktop Connection Step-by-Step Guide

RoomWizard Synchronization Software Manual Installation Instructions

ACTIVE DIRECTORY DEPLOYMENT

Integrating WebSphere Portal V8.0 with Business Process Manager V8.0

MicrosoftDynam ics GP TenantServices Installation and Adm inistration Guide

Generating an Apple Push Notification Service Certificate for use with GO!Enterprise MDM. This guide provides information on...

Setup Guide for AD FS 3.0 on the Apprenda Platform

HELP DOCUMENTATION E-SSOM DEPLOYMENT GUIDE

DESLock+ Basic Setup Guide Version 1.20, rev: June 9th 2014

APNS Certificate generating and installation

NovaBACKUP xsp Version 15.0 Upgrade Guide

RSA Security Analytics

Application Notes for Microsoft Office Communicator Clients with Avaya Communication Manager Phones - Issue 1.1

Appendix E. Captioning Manager system requirements. Installing the Captioning Manager

Steps to import MCS SSL certificates on a Sametime Server. Securing LDAP connections to and from Sametime server using SSL

O Reilly Media, Inc. 3/2/2007

Configuring a Windows 2003 Server for IAS

How to Configure a Secure Connection to Microsoft SQL Server

6421B: How to Install and Configure DirectAccess

Active Directory integration with CloudByte ElastiStor

Microsoft Exchange 2010 and 2007

Specops Command. Installation Guide

Using LDAP Authentication in a PowerCenter Domain

Installation Guide. SafeNet Authentication Service

How To - Implement Single Sign On Authentication with Active Directory

Installation Guide. . All right reserved. For more information about Specops Inventory and other Specops products, visit

Secure IIS Web Server with SSL

Deploying Remote Desktop IP Virtualization Step-by-Step Guide

LDAP Implementation AP561x KVM Switches. All content in this presentation is protected 2008 American Power Conversion Corporation

Create, Link, or Edit a GPO with Active Directory Users and Computers

Tool Tip. SyAM Management Utilities and Non-Admin Domain Users

AD RMS Windows Server 2008 to Windows Server 2008 R2 Migration and Upgrade Guide... 2 About this guide... 2

Implementation notes on Integration of Avaya Aura Application Enablement Services with Microsoft Lync 2010 Server.

Step By Step Guide: Demonstrate DirectAccess in a Test Lab

Web-Access Security Solution

Step-by-Step Guide for Setting Up VPN-based Remote Access in a

StarWind SMI-S Agent: Storage Provider for SCVMM April 2012

Entrust Managed Services PKI. Configuring secure LDAP with Domain Controller digital certificates

App Orchestration 2.5

Microsoft IIS 7 Guide to Installing Root Certificates, Generating CSR and Installing certificate

Integration Guide. Microsoft Active Directory Rights Management Services (AD RMS) Microsoft Windows Server 2008

Enable SSL for Apollo 2015

Installation and Configuration Guide

Active Directory Management. Agent Deployment Guide

Microsoft IIS 4 Guide to Installing Root Certificates, Generating CSR and Installing SSL Certificate

Scenarios for Setting Up SSL Certificates for View

Browser-based Support Console

Installing Management Applications on VNX for File

AVG Business SSO Connecting to Active Directory

Certificate Management

White Paper. Installation and Configuration of Fabasoft Folio IMAP Service. Fabasoft Folio 2015 Update Rollup 3

Cox Managed CPE Services. RADIUS Authentication for AnyConnect VPN Version 1.3 [Draft]

Installing Policy Patrol on a separate machine

RSA Authentication Manager 7.1 Microsoft Active Directory Integration Guide

STATISTICA VERSION 9 STATISTICA ENTERPRISE INSTALLATION INSTRUCTIONS FOR USE WITH TERMINAL SERVER

Digipass Plug-In for IAS. IAS Plug-In IAS. Microsoft's Internet Authentication Service. Installation Guide

Password Reset Server Installation Guide Windows 8 / 8.1 Windows Server 2012 / R2

Defender Token Deployment System Quick Start Guide

BusinessObjects Enterprise XI Release 2

Quick Start Guide for Parallels Virtuozzo

Chapter 2 Editor s Note:

LAB 1: Installing Active Directory Federation Services

WebSphere Business Monitor V7.0 Configuring a remote CEI server

Windows Intune Walkthrough: Windows Phone 8 Management

Reference and Troubleshooting: FTP, IIS, and Firewall Information

1. If there is a temporary SSL certificate in your /ServerRoot/ssl/certs/ directory, move or delete it. 2. Run the following command:

Configure Single Sign on Between Domino and WPS

How to install Small Business Server 2003 in an existing Active

Installation and Configuration Guide

Transcription:

Avaya one X Portal 1.1.3 Lightweight Directory Access Protocol (LDAP) over Secure Socket Layer (SSL) Configuration This document provides configuration steps for Avaya one X Portal s 1.1.3 communication with Active Directory using LDAP over SSL (also known as LDAPS). This configuration is an extension of an internal document for Avaya one X Portal 1.0 LDAPS configuration, with changes reflecting enhancements in WebSphere. Avaya one X Portal must be installed using LDAP, and then WebSphere must be configured with the Active Directory CA authority certificate to communicate using SSL. NOTE: For Avaya one X Portal 1.1.3, code changes were made to allow the LDAP communication to use SSL. Therefore, these instructions are not guaranteed to work on earlier versions of Avaya one X Portal. Active Directory SSL Configuration Most of what is here can found on several web pages for Microsoft. This section is almost completely copied from earlier Avaya one X Portal documentation. The following steps take you through an Active Directory configuration to enable communication using SSL. Prerequisites: The expected infrastructure: Certificate Authority installed on an Windows 2003 server Active Directory on a Windows 2003 server Obtaining a root certificate 1. Use a browser to go to the certificate authority web page. The URL is: http://<ca server>/certsrv When prompted for a user service and a password, use an account with Administrator

privileges on the CA server. 2. Click Download a CA certificate, certificate chain, or CRL. 3. Select Base 64, and then click Download CA certificate. 4. Use your browser s download function to save the certificate as a file with a.cer extension. Note: All root certificates from the same certificate authority are functionally the same. You can download a certificate once and use it repeatedly, until it expires. Opening the certificate manager 1. Navigate to Start > Run > mmc 2. On File > Add/Remove Snap in, Click Add. 3. Select Certificates and click Add 4. Select a computer account and click Next. 5. Select a local computer and click Finish. 6. Click close on the Add Standalone Snapin dialog. 7. Click OK on the Add/Remove Snap in dialog Installing the root certificate for the Certificate Authority (CA) 1. On the left side, navigate to the Certificates (Local Computer)\Trusted Root Certificate Authorities\Certificates folder 2. Select Action > Tasks > Import 3. In the Certificate Import Wizard, Click Next. 4. Click Browse, select the root certificate file, and click Open. 5. Click Next. 6. Select Place all certificates in the following store, 7. Click Browse, select Trusted Root Certificate Authorities, click OK 8. Click Next. 9. Click Finish. 10. On the right side, select the new certificate you just imported. 11. Select Action > Properties. 12. Enter a name that identifies the CA.

13. Click OK Generating a policy file for the Domain Controller on the DC machine 1. Obtain a copy of the reqdccert.vbs script. This can be found on the web at several locations. 2. From the command prompt, execute the script (Enter reqdccert.vbs ) 3. Verify that the following files have been created: <dc name>.inf, <dc name> req.bat, <dc name> vfy.bat. Editing <dc name>.inf with a text editor 1. Under the line that says [NewRequest], add a line: Subject= CN=<dc fqdn> where <dc fqdn> is the fully qualified domain name of the DC. For example: Subject= CN=chrndex01.CHEXPM.usae.avaya.com You can get the DC s FQDN from Start > Control Panel > System > Computer Name, where it is displayed as Full Computer name. Do not forget to add the prefix DN= and put the whole subject in quotes. 2. Delete the line that says Critical=2.5.29.17. (WebSphere does not recognize this extension.) 3. Save the file Creating the Certificate request on the Domain Controller 1. In the directory where the <dc name>.inf is located, execute the command: certreq new <dc name>.inf <dc name>.req 2. Copy the <dc name>.req and <dc name> req.bat file to the CA machine Creating the domain controller certificate 1. Open the command prompt, and go to the directory to where the files were copied. 2. Execute the BAT file: <dc name> req 3. When prompted to select a CA, select the CA and press OK. The script will ask you to save a file <dc name>.cer. 4. Log in to the CA, and open the Certification Authority application. This is usually under Start > Administrative Tools > Certification Authority. 5. Navigate to the Pending Requests folder. 6. Accept the request for <dc name>. 7. Navigate to the Issued Certificates folder. 8. Open the new Certificate. 9. Navigate to the detail tab, and click Copy to file; choose to export a Base 64.CER file, and export the file. Installing the Domain Controller Certificate on the Domain Controller 1. Copy the.cer file from the CA to the DC machine.

2. In the directory where the <dc name>.cer file is located, execute the command certreq accept <dc name>.cer. 3. Open the certificate manager for the local system (as described above). 4. On the left side, navigate to the Certificates (Local Computer)\Personal\Certificates folder. 5. Make sure the certificate is installed. 6. Optionally, rename the certificate (for example: Enable LDAPS). 7. Reboot the Domain Controller. WebSphere configuration Once you configure Active Directory for LDAPS, you can configure WebSphere for LDAPS, using WebSphere s IBM Console. 1) Log in to IBM s console using the administrative credentials (the credentials used when installing Avaya one X Portal). The address for the IBM s administrative console is: https://<onexportalmachine>:9043/ibm/console 2) Under the Security section, select SSL certificate and key management 3) Navigate to Key stores and certificates > NodeDefaultTrustStore > Signer certificates and click the Retrieve from port button 4) Enter the Host, Port and Alias information. The Host is the IP Address of you DC machine, and the port is the port for the LDAPS service (port 636 by default). 5) Click the Retrieve signer information button. 6) Select OK, and save the configuration. 7) Make sure that you can connect to the LDAP server by using the IBM Console to verify the connection. This test does not use Avaya one X Portal code, so it is a good validation for the environment setup. a. While still on the IBM Console site, go into the Security > Secure administration, applications, and infrastructure. If your system is already setup to talk to a single AD

environment, the Available realm definitions option should already be set to Standalone LDAP registry. b. Click the Configure button. c. Configure the parameters for your Active Directory; you do not need to save any information now. If the system is already configured to talk to the Active Directory, change the Port to be 636, and the SSL Settings to have SSL enabled. d. Click the Test connection button. If everything is right, the test should be successful. e. Log out of IBM Console. Do not change the configuration here, since changing the configuration on Avaya one X Portal will also change this configuration.

Avaya one X Portal for LDAPS configuration The Avaya one X Portal configuration is part of this setup. 1) Log in to Avaya one X Portal Admin client: https://<onexportalserver>:9443/1xp/admin 2) Select System > Enterprise Directory. Select the domain for which you need to set the LDAPS configuration. 3) Change the port to 636 and the select Secure Port. 4) Save the configuration. 5) Restart Avaya one X Portal.