Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
SSL-encrypted deployments
fiquebem
We have multiple OD Base and Receiver servers. Some of them are in the intranet, others in the public-facing Web servers and a couple in the middle (half-secure) layer, used to route deployments. (Assume they're all OD 6.2.1, on Windows.)
The powers that be want to allow only SSL-encrypted deployments and they want to prevent unauthorized sources from deploying. Questions:
1. Can we use one and the same (third-party signed) SSL certificate (along with the corresponding private key and certificate-authority certificate) on all the OD nodes without running into trouble, given that we have routed and fan-out deployments, multiple senders, etc.?
2. Since all our OD servers would receive only SSL-encrypted deployments, do we still need to enable Strict-Partner Checking?
Thanks so much for any comments! Below are additional explanations.
S.
----------------
Here's what I did on our Dev environment:
* Configured OD in 3 servers: Dev TS, Dev OD Proxy and Dev Web server; enabled and tested routed deployments in the Dev environment
* Used the OD Certificate Authority on Dev TS to generate SSL certificates; configured all the OD servers in Dev to accept only SSL-encrypted deployments
* Tested secure transfer of data via a routed deployment (from Dev TS, via Dev OD Proxy, to the Dev Web server)
I was able to do the above by using the OD "ca" script on Dev TS to generate 2 public key and private key pairs: One pair for the Certificate Authority itself (called “OD CA on TS Dev”) and one for all the OD nodes (called “OD in Dev”).
Then I copied the same “OD CA on TS Dev” public key (i.e., “certificate”) and the same “OD in Dev” certificate and private key to both Dev OD Proxy and Dev Web Server.
Next, I updated the OD Base and Receiver configuration files, along with the test deployment configuration files, to include the following parameters: sslCertificate, sslPrivateKey, sslCACertificate and sslVerifyPeer (with a value of "request" for the latter).
That all worked fine. So, in our Prod environment, we'd have the following in each OD node (and would configure each node to accept only SSL-encrypted deployments):
1. "OD-Deploy" (that is just a name) Private Key (generated by OpenDeploy)
2. "OD-Deploy" Certificate (signed by third-party. The certificate-request is
generated by OpenDeploy but the certificate is signed by third-party)
3. Certificate Authority Certificate (of third-party)
Would that work? One difference from Dev is that, in Prod, the certificate is signed by a third-party. Also, in Prod, we have a bunch of Receivers and multiple Base servers.
--
Find more posts tagged with
Comments
There are no comments yet