01.06.2013 Views

OpenEdge Getting Started: Installation and Configuration - Product ...

OpenEdge Getting Started: Installation and Configuration - Product ...

OpenEdge Getting Started: Installation and Configuration - Product ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Managing <strong>OpenEdge</strong> Key <strong>and</strong> Certificate<br />

Stores<br />

All <strong>OpenEdge</strong> server <strong>and</strong> client components that implement Secure HTTP (HTTPS) or<br />

Secure Socket Layer (SSL) connections require access to private keys <strong>and</strong> digital<br />

certificates to negotiate these connections <strong>and</strong> to enable them to function securely.<br />

<strong>OpenEdge</strong> <strong>Getting</strong> <strong>Started</strong>: <strong>Installation</strong> <strong>and</strong> <strong>Configuration</strong> 261<br />

9<br />

For all <strong>OpenEdge</strong> components, <strong>OpenEdge</strong> provides utilities that allow you to install <strong>and</strong><br />

manage keys <strong>and</strong> digital certificates (in key stores <strong>and</strong> certificate stores) so the<br />

components can access them. For Open Clients, clients of <strong>OpenEdge</strong> Web services,<br />

<strong>OpenEdge</strong> provides utilities for some clients or it relies on utilities provided by the client<br />

platform to manage the required certificate stores.<br />

This chapter describes how to use the <strong>OpenEdge</strong> utilities, as detailed in the following<br />

sections:<br />

• Managing key stores for <strong>OpenEdge</strong> servers<br />

• Managing certificate stores for <strong>OpenEdge</strong> clients <strong>and</strong> servers<br />

An SSL server requires access to a private key <strong>and</strong> a digital (public-key) certificate to<br />

authorize the identity of the server. Clients require access to public-key certificates that<br />

allow them to authenticate the servers that they access. Both servers <strong>and</strong> clients must<br />

obtain their keys <strong>and</strong> certificates from a trusted source, a Certificate Authority (CA).<br />

The server can trust the CA to authorize the server’s identity <strong>and</strong> the client can trust the<br />

CA to provide proof of the server’s identity. For more information on keys, certificates,<br />

<strong>and</strong> how CAs support them, see the chapters on security in <strong>OpenEdge</strong> <strong>Getting</strong> <strong>Started</strong>:<br />

Core Business Services - Security <strong>and</strong> Auditing.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!