22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

178 Lotus Security Handbook<br />

When SSL is utilized in a reverse proxy environment with Sametime, much of the<br />

Sametime functionality will run within the Java Plug-in on the Web browser (that<br />

is, the connect client, meetings client, and so forth). This Java Plug-in must be<br />

made aware of the SSL certificates utilized by the reverse proxy so that it can<br />

communicate via SSL.<br />

The certificates that the Java Plug-in may need to be aware of are:<br />

Signer certificates<br />

When a reverse proxy server is configured to support SSL, the reverse proxy<br />

server sends an SSL server certificate to the Web browser during the SSL<br />

connection handshake. The Java 1.4.1 Plug-in used by the Web browser must<br />

have access to a Signer certificate that is signed by the same Certificate<br />

Authority (CA) as the server certificate that is sent by the reverse proxy.<br />

By default, the Java Plug-in has access to several different Signer certificates<br />

that can be used for this purpose. To view the Signer certificates that are<br />

available to the Java Plug-in 1.4.1, use the Java Plug-in Control Panel as follows:<br />

1. From the Windows desktop, open the Control Panel (Select Start →<br />

Settings → Control Panel).<br />

2. Double-click the Java Plug-in 1.4.1 icon to open the Java Plug-in Control<br />

Panel.<br />

3. Click the Certificates tab.<br />

4. Select the Signer CA radio button.<br />

The server certificate sent by the reverse proxy server to the client Web browser<br />

must be signed by one of the CAs that appears in the signer CA list for the SSL<br />

connection handshake to succeed.<br />

Client certificate authentication issues<br />

If the reverse proxy server is configured to require client certificate<br />

authentication, the client certificate for an individual user must be imported into<br />

the Java Plug-in 1.4.1 Control Panel on that user's machine. You can use the<br />

Certificates tab of the Java Plug-in Control Panel to import the client certificate<br />

into the Java Plug-in key store. For example:<br />

1. From the Windows desktop on a user's machine, open the Control Panel<br />

(Select Start → Settings → Control Panel).<br />

2. Double-click the Java Plug-in 1.4.1 icon to open the Java Plug-in Control<br />

Panel.<br />

3. Click the Certificates tab.<br />

4. In the Certificates column, select Secure Site.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!