ibm-information-center/dist/eclipse/plugins/i5OS.ic.rzain_5.4.0.1/scenariodetails.htm

151 lines
9.0 KiB
HTML
Raw Permalink Normal View History

2024-04-02 14:02:31 +00:00
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE html
PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html lang="en-us" xml:lang="en-us">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<meta name="security" content="public" />
<meta name="Robots" content="index,follow" />
<meta http-equiv="PICS-Label" content='(PICS-1.1 "http://www.icra.org/ratingsv02.html" l gen true r (cz 1 lz 1 nz 1 oz 1 vz 1) "http://www.rsac.org/ratingsv01.html" l gen true r (n 0 s 0 v 0 l 0) "http://www.classify.org/safesurf/" l gen true r (SS~~000 1))' />
<meta name="DC.Type" content="task" />
<meta name="DC.Title" content="Configuration details: Secure a client connection to your Management Central server with SSL" />
<meta name="abstract" content="This topic shows the expanded configurations steps for using SSL to secure a client connection to your Management Central server." />
<meta name="description" content="This topic shows the expanded configurations steps for using SSL to secure a client connection to your Management Central server." />
<meta name="DC.Relation" scheme="URI" content="secclientmc.htm" />
<meta name="DC.Relation" scheme="URI" content="rzainplanssl.htm#rzainrequiredprogs" />
<meta name="DC.Relation" scheme="URI" content="../rzahu/rzahudcmfirsttime.htm" />
<meta name="DC.Relation" scheme="URI" content="rzainmc.htm#before" />
<meta name="copyright" content="(C) Copyright IBM Corporation 2002, 2006" />
<meta name="DC.Rights.Owner" content="(C) Copyright IBM Corporation 2002, 2006" />
<meta name="DC.Format" content="XHTML" />
<meta name="DC.Identifier" content="scenariodetails" />
<meta name="DC.Language" content="en-us" />
<!-- All rights reserved. Licensed Materials Property of IBM -->
<!-- US Government Users Restricted Rights -->
<!-- Use, duplication or disclosure restricted by -->
<!-- GSA ADP Schedule Contract with IBM Corp. -->
<link rel="stylesheet" type="text/css" href="./ibmdita.css" />
<link rel="stylesheet" type="text/css" href="./ic.css" />
<title>Configuration details: Secure a client connection to your Management
Central server with SSL</title>
</head>
<body id="scenariodetails"><a name="scenariodetails"><!-- --></a>
<!-- Java sync-link --><script language="Javascript" src="../rzahg/synch.js" type="text/javascript"></script>
<h1 class="topictitle1">Configuration details: Secure a client connection to your Management
Central server with SSL</h1>
<div><p>This topic shows the expanded configurations steps for using SSL
to secure a client connection to your Management Central server.</p>
<div class="p"><p>The following information assumes you have read through the <a href="secclientmc.htm#secclientmc">Scenario: Secure a client connection to
your Management Central server with SSL</a>. </p>
</div>
<div class="section"> <p>In this scenario, an iSeries™ server is specified as the central
system in a company's local area network (LAN). Bob uses the Management Central
server on the central system (referred to here as System A) to manage the
endpoints on the company network. The following information explains how to
perform the steps required to secure an external client connection to the
Management Central server. Follow along as Bob completes the scenario configuration
steps.</p>
</div>
</div>
<div>
<div class="familylinks">
<div class="parentlink"><strong>Parent topic:</strong> <a href="secclientmc.htm" title="Use the information in this scenario to use SSL to secure a connection between a remote client and your server.">Scenario: Secure a client connection to your Management Central server with SSL</a></div>
</div>
<div class="relconcepts"><strong>Related concepts</strong><br />
<div><a href="rzainplanssl.htm#rzainrequiredprogs">SSL prerequisites</a></div>
</div>
<div class="reltasks"><strong>Related tasks</strong><br />
<div><a href="rzainmc.htm#before">Prerequisites and assumptions:</a></div>
</div>
<div class="relinfo"><strong>Related information</strong><br />
<div><a href="../rzahu/rzahudcmfirsttime.htm">Set up certificates for the first time</a></div>
</div>
</div><div class="nested1" xml:lang="en-us" id="step1"><a name="step1"><!-- --></a><h2 class="sectionscenariobar">Step 1: Deactivate SSL for the iSeries Navigator
client</h2>
<div><div class="p">This step is only necessary if you have already enabled SSL for the iSeries Navigator
client.</div>
<ol><li><span>In iSeries Navigator,
expand <span class="uicontrol">My Connections</span>.</span></li>
<li><span>Right-click System A and select <span class="uicontrol">Properties</span>.</span></li>
<li><span>Click the <span class="uicontrol">Secure Sockets</span> tab and deselect <span class="uicontrol">Use
Secure Sockets Layer (SSL) for connection</span>.</span></li>
<li><span>Exit iSeries Navigator
and restart it.</span></li>
</ol>
<div class="section"><p>The padlock disappears from the Management Central container in iSeries Navigator,
indicating an unsecured connection. This indicates to Bob that he no longer
has an SSL-secured connection between his client and the central system of
his company.</p>
</div>
</div>
</div>
<div class="nested1" xml:lang="en-us" id="step2"><a name="step2"><!-- --></a><h2 class="sectionscenariobar">Step 2: Set the authentication level
for the Management Central server</h2>
<div><ol><li><span>In iSeries Navigator,
right-click <span class="uicontrol">Management Central</span>, and select <span class="uicontrol">Properties</span>.</span></li>
<li><span>Click the <span class="uicontrol">Security</span> tab, and select <span class="uicontrol">Use
Secure Sockets Layer (SSL)</span>.</span></li>
<li><span>Select <span class="uicontrol">Any</span> for the authentication level
(available on V5R3 or later of iSeries Access for Windows<sup>®</sup>).</span></li>
<li><span>Click <span class="uicontrol">OK</span> to set this value on the central
system.</span></li>
</ol>
</div>
</div>
<div class="nested1" xml:lang="en-us" id="step3"><a name="step3"><!-- --></a><h2 class="sectionscenariobar">Step 3: Restart the Management Central
server on the central system</h2>
<div><ol><li><span>In iSeries Navigator,
expand <span class="uicontrol">My Connections</span>.</span></li>
<li><span>On System A, expand <span class="uicontrol">Network--&gt;Servers</span> and
select <span class="uicontrol">TCP/IP</span>.</span></li>
<li><span>Right-click <span class="uicontrol">Management Central</span> and select <span class="uicontrol">Stop</span>.
The central system view collapses, and a message displays, explaining you
are not connected to the server.</span></li>
<li><span>After the Management Central server has stopped, click <span class="uicontrol">Start</span> to
restart it.</span></li>
</ol>
</div>
</div>
<div class="nested1" xml:lang="en-us" id="step4"><a name="step4"><!-- --></a><h2 class="sectionscenariobar">Step 4: Activate SSL for the iSeries Navigator
client</h2>
<div><ol><li><span>In iSeries Navigator,
expand <span class="uicontrol">My Connections</span>.</span></li>
<li><span>Right-click System A and select <span class="uicontrol">Properties</span>.</span></li>
<li><span>Click the <span class="uicontrol">Secure Sockets</span> tab and select <span class="uicontrol">Use
Secure Sockets Layer (SSL) for connection</span>.</span></li>
<li><span>Exit iSeries Navigator
and restart it.</span></li>
</ol>
<div class="section"><p>A padlock appears next to the Management Central server in iSeries Navigator,
indicating an SSL-secured connection. This indicates to Bob that he has successfully
activated an SSL-secured connection between his client and the central system
of his company. </p>
<div class="note"><span class="notetitle">Note:</span> This procedure only secures the connection between
one PC and the Management Central server. Other client connections with the
Management Central server, as well as connections from endpoints to the Management
Central server, will not be secure. To secure other clients, ensure they meet
the prerequisites and repeat <a href="scenariodetails.htm#step4">Step 4: Activate SSL for the iSeries Navigator client</a>.
To secure other connections with the Management Central server, see <a href="rzainmc.htm#mc">Scenario: Secure all connections to your Management
Central server with SSL</a>.</div>
</div>
</div>
</div>
<div class="nested1" xml:lang="en-us" id="optional1"><a name="optional1"><!-- --></a><h2 class="sectionscenariobar">Optional step: Deactivate SSL for
the iSeries Navigator
client</h2>
<div><div class="section">If Bob wants to work from the company office and does not want an
SSL connection affecting the performance of his PC, he can easily deactivate
it by performing the following steps:</div>
<ol><li><span>In iSeries Navigator,
expand <span class="uicontrol">My Connections</span>.</span></li>
<li><span>Right-click System A and select <span class="uicontrol">Properties</span>.</span></li>
<li><span>Click the <span class="uicontrol">Secure Sockets</span> tab and deselect <span class="uicontrol">Use
Secure Sockets Layer (SSL) for connection</span>.</span></li>
<li><span>Exit iSeries Navigator
and restart it.</span></li>
</ol>
</div>
</div>
</body>
</html>