background image

Configuring FCS for SSL

23

Server.xml

SSLCACertificatePath

[none]

Specifies the name of a 
directory containing CA 
certificates. Each file in the 
directory must contain only a 
single CA certificate, and the 
files must be named by the 
subject name's hash and an 
extension of ".0". 
Win32 Only: If this tag is empty, 
FCS attempts to find CA 
certificates in the certs directory 
located at the same level as the 
conf directory. The Windows 
cert store can be imported into 
this directory by running 
FCSMaster -console -initialize 
from the command line.

Server.xml

SSLRandomSeed

16

Specifies the number of bytes of 
entropy to use for seeding the 
pseudo–random number 
generator (PRNG). Entropy is a 
measure of randomness. The 
more entropy, the more random 
numbers from the PRNG will be.
The default number is 16. You 
cannot specify less than 8 bytes, 

Server.xml

SSLSessionCacheGC

5

Specifies in minutes how often 
to flush expired sessions from 
the server-side session cache.

FCS File

XML Tag

Default Description

Summary of Contents for BREEZE 5

Page 1: ...Installing and Configuring Breeze Edge Server...

Page 2: ...n you do so at your own risk Macromedia provides these links only as a convenience and the inclusion of the link does not imply that Macromedia endorses or accepts any responsibility for the content o...

Page 3: ...ervers 8 System requirements 8 Installing Breeze Edge Server 9 The Breeze Edge Server license file 14 Configuring FCS for Breeze Edge Server 14 Configuring FCS for SSL 16 Stopping and starting Breeze...

Page 4: ...4 Contents...

Page 5: ...ge Server on page 9 The Breeze Edge Server license file on page 14 Configuring FCS for Breeze Edge Server on page 14 Mapping the DNS entry for Breeze Edge Server on page 15 Configuring FCS for SSL on...

Page 6: ...che it returns the Breeze Meeting data to the requesting client the user s computer without calling upon the Breeze server This detour to the Breeze server is transparent to users In this scenario no...

Page 7: ...deployment might have multiple edge servers installed For example one edge server might aggregate and forward requests from San Francisco and another might aggregate and forward requests from Boston...

Page 8: ...Breeze Meeting directly The edge server in turn connects to the origin Breeze server Many additional steps such as user authentication and permissions authorization are hidden from the Breeze user Edg...

Page 9: ...ose all other applications before starting to install To install and configure Breeze Edge Server 1 Insert the installation CD into the CD ROM drive If the Macromedia Breeze Edge Server Setup wizard d...

Page 10: ...dia Breeze Edge Server 2 Click Next to continue The License Agreement window appears 3 Read the agreement select I Accept the Agreement and click Next to continue The Select Destination Location windo...

Page 11: ...lt installation location or click Browse to select a different location and then click Next If the wizard detects a previous installation of a Breeze Edge Server you will see the following screen 5 Cl...

Page 12: ...select a different location and then click Next The Ready to Install window alerts you that the Breeze installation is about to begin 7 Review the choices for the destination folder where Breeze will...

Page 13: ...s beginning to extract the Breeze Edge Server files on the installation CD and install them This process takes less than two minutes 9 Click Cancel at any time if you want to abort or cancel the insta...

Page 14: ...n edge server s IP address when resolving the Domain Name Server DNS entry for the BREEZEHOST variable formerly known as ADMIN_HOST Here is a scenario for large Breeze deployments that builds upon the...

Page 15: ...rver 80 is the IP address or domain name and port number of the machine where the Breeze server is installed The value for this variable configures the edge server to connect to the Breeze server at t...

Page 16: ...vate documents over the Internet you must configure the FCS Adaptor xml and Server xml files for native SSL support by defining the appropriate SSL tags For example the default settings for the Redire...

Page 17: ...Ctx SSLCertificateFile SSLCertificateFile SSLCertificateKeyFile type PEM SSLCertificateKeyFile SSLPassPhrase SSLPassPhrase SSLCipherSuite SSLCipherSuite SSLSessionTimeout 5 SSLSessionTimeout SSLServer...

Page 18: ...rected traffic A request for redirection to a specific host can be Redirect enable false Host port 80 8080 Host Host port 443 8443 Host Redirect Adaptor xml SSLCertificateFile none Specifies the locat...

Page 19: ...pings For a list of components see the FCS documentation The default setting for this tag is ALL ADH LOW EXP MD5 STRE NGTH Contact Breeze Technical Support before changing the default settings Adaptor...

Page 20: ...sues certificates to people A certificate is normally signed by a CA The CA is saying that the owner of the certificate is who he says he is The CA has done the necessary research and background check...

Page 21: ...OpenSSL To import these certificates you run FCSMaster console initialize This will import the certificates from the Windows certificate store to the directory specified by this configuration tag If...

Page 22: ...is ALL ADH LOW EXP MD5 STRENGTH Contact Breeze Technical Support before changing the default settings Server xml SSLEngine none Specifies the cryptographic accelerator to use if any The following cryp...

Page 23: ...s the conf directory The Windows cert store can be imported into this directory by running FCSMaster console initialize from the command line Server xml SSLRandomSeed 16 Specifies the number of bytes...

Page 24: ...started Server xml SSLVerifyCertificate true Configures the server to act as an SSL client out going SSL connections The tag specifies whether or not to verify the certificate that is returned by the...

Page 25: ...server cluster Macromedia Breeze provides support for clustering edge servers If your license permits it you can set up install and configure a cluster of edge servers on multiple networked computers...

Page 26: ...onfigure the load balancer Scheduling maintenance Macromedia recommends that you create a weekly scheduled task to clear the edge server cache To create this scheduled task 1 Create a cache bat file t...

Reviews: