data:image/s3,"s3://crabby-images/ce2eb/ce2eb2bb48402dcaa23988adad56fcfc877ad727" alt="Adobe 65029121 - Flash Media Streaming Server Configuration And Administration Manual Download Page 46"
42
FLASH
MEDIA
SERVER
4.5
CONFIGURATION
AND
ADMINISTRATION
Configuring the server
Last updated 11/28/2012
Configure adaptors to manage outgoing SSL connections independently
The
SSL
section in the Server.xml file configures all adaptors to use the same settings. However, you might want to use
a different certificate for each virtual host. In this case, assign one virtual host to each adaptor and configure your
adaptors individually to override the settings in the Server.xml file.
❖
Copy the
SSL
section in the Server.xml file to the Adaptor.xml files and enter the new values. You don’t need to
copy the
SSLRandomSeed
tag, as this tag is a server-level setting that cannot be overridden in Adaptor.xml.
Configure virtual hosts to manage outgoing SSL connections independently
For example, you can disable certificate checking in one virtual host, use a certificate in a different folder for one virtual
host, and implement a different set of ciphers in a third virtual host.
1
Uncomment the
SSL
section under the
Proxy
tag in the appropriate Vhost.xml file:
Element
Description
SSLRandomSeed
The number of bytes of entropy to use for seeding the pseudo-random number generator
(PRNG). You cannot specify anything less than 8 bytes, and the default value is 16. Entropy is a
measure of randomness. The more entropy, the more random numbers the PRNG will contain.
The server may take longer to start up if you specify a large number.
SSLSessionCacheGC
How often to flush expired sessions from the server-side session cache, in minutes.
SSLVerifyCertificate
A Boolean value specifying whether to verify the certificate returned by the server being
connected to (
true
) or not (
false
). The default value is
true
. Disabling certificate verification
can result in a security hazard. Do not disable verification unless you are certain you understand
the ramifications.
SSLCACertificatePath
A folder containing certificates. Each file in the folder must contain only a single certificate, and
the file name must be hash and the extension ".0", for example, e98140a6.0.
On a Windows 32-bit operating system, if this tag is empty, the server looks for certificates in the
rootinstall
\certs directory. You can import the Windows certificate store to the certs directory by
running
FMSMaster -console -initialize
from a command line.
In Linux, you must specify the location of the certificates.
SSLCACertificateFile
Specifies the name of a file containing one or more certificates in PEM format.
SSLVerifyDepth
Specifies the maximum depth of an acceptable certificate. If a self-signed root certificate cannot
be found within this depth, certificate verification fails. The default value is 9.
SSLCipherSuite
The SSL ciphers: a colon-delimited list of components. A component can be a key exchange
algorithm, authentication method, encryption method, digest type, or one of a selected number
of aliases for common groupings. Do not change the default settings unless you are very familiar
with SSL ciphers. The possible values are listed here: “
SSLCipherSuite
” on page
225.