1. Add a custom certificate for SSL/TLS connections
2. Back up a custom certificate
3. Restore a custom certificate
•
•
Enable OCP/RMI session locking
•
Restrict RMI access for the administrator and security users
Enabling secure communications
Enable or disable secure access to the RMI using Secure Socket Layer (SSL) or Secure Shell (SSH). The
default is disabled.
When SSH is enabled, the library will only accept SSH connections. The default is disabled. A service
user login is required to enable SSH.
NOTE:
When Data Verification is enabled, Command View TL communicates with the library though SSH even
when SSH is disabled in this screen. However, when SSH is disabled in this screen, console and remote
access for SSH connections is disabled.
Procedure
1.
Navigate to the RMI
Configuration > Web Management
screen.
2.
In the
Secure Communications
section, select
SSL (Secure Socket Layer)
to require all
connections to the RMI to use HTTPS.
3.
Click
Submit
.
Adding a signed certificate for SSL/TLS connections
Use the Add Signed Certificate Wizard to add a self-signed certificate to the library for use with SSL/TLS
connections. The certificate will be used by the library for https connections to the RMI and Data
Verification connections to Command View TL.
NOTE:
KMIP SSL/TLS connections will not use this certificate because they use a different set of certificates that
are paired with the KMIP server.
The certificate will also be used on the client side of the connection and will need to be applied to each
server or computer where the web browser will be used to access the RMI.
The wizard generates a certificate and then you will need a Certificate Authority to sign the certificate.
Procedure
1.
Before starting the wizard, prepare your Certificate Authority to sign the certificate. You will paste the
certificate generated by the wizard into a field in the Certificate Authority for signing.
2.
To start the wizard click
Start Certificate Wizard
from the
Configuration > Web Management
screen.
Enabling secure communications
91