30.01.2015 Views

Picture Perfect 4.6 User Manual - UTCFS Global Security Products

Picture Perfect 4.6 User Manual - UTCFS Global Security Products

Picture Perfect 4.6 User Manual - UTCFS Global Security Products

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 4<br />

Setup<br />

57<br />

Setting up SSL encryption<br />

Note:<br />

This section describes how to set up SSL encryption on <strong>Picture</strong> <strong>Perfect</strong> systems (stand-alone, redundant, and<br />

Enterprise configurations). <br />

Refer to Chapter 6 of the <strong>Picture</strong> <strong>Perfect</strong> <strong>4.6</strong> Installation <strong>Manual</strong> for the following procedures: <br />

-- SSL configuration for Facility Commander 2.2.3 and <strong>Picture</strong> <strong>Perfect</strong> 4.5.1 & <strong>4.6</strong> (stand-alone)<br />

-- Using a CA certificate on <strong>Picture</strong> <strong>Perfect</strong> <strong>4.6</strong> for SSL)<br />

Disabling IPv6 on Linux<br />

IPv6 should be disabled on Linux for client login with SSL enabled.<br />

1. Disable IPv6 through the network configuration GUI.<br />

2. Make sure the following settings are applied:<br />

• The /etc/sysconfig/network file contains the following entry:<br />

NETWORKING_IPV6=no<br />

• The /etc/modprobe.conf file contains the following entry:<br />

alias net-pf-10 off<br />

options ipv6 disable=1<br />

3. Reboot the system.<br />

4. When the system is back up, run ifconfig and verify that there are no IPv6 entries.<br />

Client SSL encryption<br />

The activation and deactivation of SSL encryption for events and requests transmitted between the<br />

<strong>Picture</strong> <strong>Perfect</strong> host and its clients is controlled by the EnableSSL script. This script can be run<br />

anytime after <strong>Picture</strong> <strong>Perfect</strong> has been installed.<br />

Note:<br />

Turning on Client SSL Encryption has a negative impact on client performance.<br />

To activate client SSL encryption:<br />

1. Log on to the system as ppadmin.<br />

2. At the command prompt, stop <strong>Picture</strong> <strong>Perfect</strong> by typing:<br />

rc.pperf -k<br />

If this is a redundant configuration, stop <strong>Picture</strong> <strong>Perfect</strong> by typing:<br />

pprscmd stop<br />

3. Log on to the system as root by typing:<br />

su - root<br />

4. Type the following command to enable SSL:<br />

EnableSSL 1<br />

Enter<br />

Enter<br />

5. Log on to the system as ppadmin.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!