151 lines
9.0 KiB
HTML
151 lines
9.0 KiB
HTML
<?xml version="1.0" encoding="UTF-8"?>
|
|
<!DOCTYPE html
|
|
PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
|
|
<html lang="en-us" xml:lang="en-us">
|
|
<head>
|
|
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
|
|
<meta name="security" content="public" />
|
|
<meta name="Robots" content="index,follow" />
|
|
<meta http-equiv="PICS-Label" content='(PICS-1.1 "http://www.icra.org/ratingsv02.html" l gen true r (cz 1 lz 1 nz 1 oz 1 vz 1) "http://www.rsac.org/ratingsv01.html" l gen true r (n 0 s 0 v 0 l 0) "http://www.classify.org/safesurf/" l gen true r (SS~~000 1))' />
|
|
<meta name="DC.Type" content="task" />
|
|
<meta name="DC.Title" content="Configuration details: Secure a client connection to your Management Central server with SSL" />
|
|
<meta name="abstract" content="This topic shows the expanded configurations steps for using SSL to secure a client connection to your Management Central server." />
|
|
<meta name="description" content="This topic shows the expanded configurations steps for using SSL to secure a client connection to your Management Central server." />
|
|
<meta name="DC.Relation" scheme="URI" content="secclientmc.htm" />
|
|
<meta name="DC.Relation" scheme="URI" content="rzainplanssl.htm#rzainrequiredprogs" />
|
|
<meta name="DC.Relation" scheme="URI" content="../rzahu/rzahudcmfirsttime.htm" />
|
|
<meta name="DC.Relation" scheme="URI" content="rzainmc.htm#before" />
|
|
<meta name="copyright" content="(C) Copyright IBM Corporation 2002, 2006" />
|
|
<meta name="DC.Rights.Owner" content="(C) Copyright IBM Corporation 2002, 2006" />
|
|
<meta name="DC.Format" content="XHTML" />
|
|
<meta name="DC.Identifier" content="scenariodetails" />
|
|
<meta name="DC.Language" content="en-us" />
|
|
<!-- All rights reserved. Licensed Materials Property of IBM -->
|
|
<!-- US Government Users Restricted Rights -->
|
|
<!-- Use, duplication or disclosure restricted by -->
|
|
<!-- GSA ADP Schedule Contract with IBM Corp. -->
|
|
<link rel="stylesheet" type="text/css" href="./ibmdita.css" />
|
|
<link rel="stylesheet" type="text/css" href="./ic.css" />
|
|
<title>Configuration details: Secure a client connection to your Management
|
|
Central server with SSL</title>
|
|
</head>
|
|
<body id="scenariodetails"><a name="scenariodetails"><!-- --></a>
|
|
<!-- Java sync-link --><script language="Javascript" src="../rzahg/synch.js" type="text/javascript"></script>
|
|
<h1 class="topictitle1">Configuration details: Secure a client connection to your Management
|
|
Central server with SSL</h1>
|
|
<div><p>This topic shows the expanded configurations steps for using SSL
|
|
to secure a client connection to your Management Central server.</p>
|
|
<div class="p"><p>The following information assumes you have read through the <a href="secclientmc.htm#secclientmc">Scenario: Secure a client connection to
|
|
your Management Central server with SSL</a>. </p>
|
|
</div>
|
|
<div class="section"> <p>In this scenario, an iSeries™ server is specified as the central
|
|
system in a company's local area network (LAN). Bob uses the Management Central
|
|
server on the central system (referred to here as System A) to manage the
|
|
endpoints on the company network. The following information explains how to
|
|
perform the steps required to secure an external client connection to the
|
|
Management Central server. Follow along as Bob completes the scenario configuration
|
|
steps.</p>
|
|
</div>
|
|
</div>
|
|
<div>
|
|
<div class="familylinks">
|
|
<div class="parentlink"><strong>Parent topic:</strong> <a href="secclientmc.htm" title="Use the information in this scenario to use SSL to secure a connection between a remote client and your server.">Scenario: Secure a client connection to your Management Central server with SSL</a></div>
|
|
</div>
|
|
<div class="relconcepts"><strong>Related concepts</strong><br />
|
|
<div><a href="rzainplanssl.htm#rzainrequiredprogs">SSL prerequisites</a></div>
|
|
</div>
|
|
<div class="reltasks"><strong>Related tasks</strong><br />
|
|
<div><a href="rzainmc.htm#before">Prerequisites and assumptions:</a></div>
|
|
</div>
|
|
<div class="relinfo"><strong>Related information</strong><br />
|
|
<div><a href="../rzahu/rzahudcmfirsttime.htm">Set up certificates for the first time</a></div>
|
|
</div>
|
|
</div><div class="nested1" xml:lang="en-us" id="step1"><a name="step1"><!-- --></a><h2 class="sectionscenariobar">Step 1: Deactivate SSL for the iSeries Navigator
|
|
client</h2>
|
|
<div><div class="p">This step is only necessary if you have already enabled SSL for the iSeries Navigator
|
|
client.</div>
|
|
<ol><li><span>In iSeries Navigator,
|
|
expand <span class="uicontrol">My Connections</span>.</span></li>
|
|
<li><span>Right-click System A and select <span class="uicontrol">Properties</span>.</span></li>
|
|
<li><span>Click the <span class="uicontrol">Secure Sockets</span> tab and deselect <span class="uicontrol">Use
|
|
Secure Sockets Layer (SSL) for connection</span>.</span></li>
|
|
<li><span>Exit iSeries Navigator
|
|
and restart it.</span></li>
|
|
</ol>
|
|
<div class="section"><p>The padlock disappears from the Management Central container in iSeries Navigator,
|
|
indicating an unsecured connection. This indicates to Bob that he no longer
|
|
has an SSL-secured connection between his client and the central system of
|
|
his company.</p>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
<div class="nested1" xml:lang="en-us" id="step2"><a name="step2"><!-- --></a><h2 class="sectionscenariobar">Step 2: Set the authentication level
|
|
for the Management Central server</h2>
|
|
<div><ol><li><span>In iSeries Navigator,
|
|
right-click <span class="uicontrol">Management Central</span>, and select <span class="uicontrol">Properties</span>.</span></li>
|
|
<li><span>Click the <span class="uicontrol">Security</span> tab, and select <span class="uicontrol">Use
|
|
Secure Sockets Layer (SSL)</span>.</span></li>
|
|
<li><span>Select <span class="uicontrol">Any</span> for the authentication level
|
|
(available on V5R3 or later of iSeries Access for Windows<sup>®</sup>).</span></li>
|
|
<li><span>Click <span class="uicontrol">OK</span> to set this value on the central
|
|
system.</span></li>
|
|
</ol>
|
|
</div>
|
|
</div>
|
|
<div class="nested1" xml:lang="en-us" id="step3"><a name="step3"><!-- --></a><h2 class="sectionscenariobar">Step 3: Restart the Management Central
|
|
server on the central system</h2>
|
|
<div><ol><li><span>In iSeries Navigator,
|
|
expand <span class="uicontrol">My Connections</span>.</span></li>
|
|
<li><span>On System A, expand <span class="uicontrol">Network-->Servers</span> and
|
|
select <span class="uicontrol">TCP/IP</span>.</span></li>
|
|
<li><span>Right-click <span class="uicontrol">Management Central</span> and select <span class="uicontrol">Stop</span>.
|
|
The central system view collapses, and a message displays, explaining you
|
|
are not connected to the server.</span></li>
|
|
<li><span>After the Management Central server has stopped, click <span class="uicontrol">Start</span> to
|
|
restart it.</span></li>
|
|
</ol>
|
|
</div>
|
|
</div>
|
|
<div class="nested1" xml:lang="en-us" id="step4"><a name="step4"><!-- --></a><h2 class="sectionscenariobar">Step 4: Activate SSL for the iSeries Navigator
|
|
client</h2>
|
|
<div><ol><li><span>In iSeries Navigator,
|
|
expand <span class="uicontrol">My Connections</span>.</span></li>
|
|
<li><span>Right-click System A and select <span class="uicontrol">Properties</span>.</span></li>
|
|
<li><span>Click the <span class="uicontrol">Secure Sockets</span> tab and select <span class="uicontrol">Use
|
|
Secure Sockets Layer (SSL) for connection</span>.</span></li>
|
|
<li><span>Exit iSeries Navigator
|
|
and restart it.</span></li>
|
|
</ol>
|
|
<div class="section"><p>A padlock appears next to the Management Central server in iSeries Navigator,
|
|
indicating an SSL-secured connection. This indicates to Bob that he has successfully
|
|
activated an SSL-secured connection between his client and the central system
|
|
of his company. </p>
|
|
<div class="note"><span class="notetitle">Note:</span> This procedure only secures the connection between
|
|
one PC and the Management Central server. Other client connections with the
|
|
Management Central server, as well as connections from endpoints to the Management
|
|
Central server, will not be secure. To secure other clients, ensure they meet
|
|
the prerequisites and repeat <a href="scenariodetails.htm#step4">Step 4: Activate SSL for the iSeries Navigator client</a>.
|
|
To secure other connections with the Management Central server, see <a href="rzainmc.htm#mc">Scenario: Secure all connections to your Management
|
|
Central server with SSL</a>.</div>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
<div class="nested1" xml:lang="en-us" id="optional1"><a name="optional1"><!-- --></a><h2 class="sectionscenariobar">Optional step: Deactivate SSL for
|
|
the iSeries Navigator
|
|
client</h2>
|
|
<div><div class="section">If Bob wants to work from the company office and does not want an
|
|
SSL connection affecting the performance of his PC, he can easily deactivate
|
|
it by performing the following steps:</div>
|
|
<ol><li><span>In iSeries Navigator,
|
|
expand <span class="uicontrol">My Connections</span>.</span></li>
|
|
<li><span>Right-click System A and select <span class="uicontrol">Properties</span>.</span></li>
|
|
<li><span>Click the <span class="uicontrol">Secure Sockets</span> tab and deselect <span class="uicontrol">Use
|
|
Secure Sockets Layer (SSL) for connection</span>.</span></li>
|
|
<li><span>Exit iSeries Navigator
|
|
and restart it.</span></li>
|
|
</ol>
|
|
</div>
|
|
</div>
|
|
|
|
</body>
|
|
</html> |