Forcing traffic to be sent over SSL
Although HCL Docs supports both http and https protocols, it is best to force https traffic. To force https, you must first configure the HTTP server.
Procedure
- Configure HTTP Server.
- For IBM HTTP Server, configure it according to the instructions in the technote Rewriting HTTP (port 80) requests to HTTPS (port 443).
- If you are using another HTTP server, refer to the appropriate documentation.
- Optional: Configure WebSphere server. To force
https traffic, set security for WebSphere cookies by completing one
of the following procedures:
- To secure session cookies, complete the following steps:
- Log in as administrator to the WebSphere Application Server Integrated Solutions Console of the server hosting HCL Connections.
- Select .
- Select the server hosting HCL Docs, Viewer, and Conversion from the list of server names.
- Click Session Management, and then click Enable cookies.
- Select the Restrict cookies to HTTPS sessions check box.
- Click Apply, and then click OK.
- To secure LTPA tokens, complete the following steps:
- From the WebSphere Application Server Integrated Solutions Console, expand Security, and then click Global security.
- Expand Web and SIP security, and then click single sign-on (SSO).
- Select the Requires SSL check box.
- Click Apply, and then click OK.
- To secure session cookies, complete the following steps:
- Configure HCL Docs, Viewer,
and Conversion. If you force https traffic, you must also change the HCL Docs cookies configuration
as following:
- Log in to the WebSphere Deployment Manager server.
- Open <WAS_HOME>/profiles/<DMGR>/config/cells/{cellname}/IBMDocs-config/.
- Change http to https in urls of concord-config.json, viewer-config.json, conversion-config.json, docs-daemon-config.json and viewer-daemon-config.json.
- Open the WebSphere console and click .
- Click . Select Docs cluster, Viewer cluster and Conversion cluster, and then restart them.
- Go to News Application. . Restart
- Configure CMIS properties. If the environment has CMIS installed, you must check the configuration in <WAS_HOME>/profiles/<AppSrv>/installedApps/{cellname}/fncmis.ear/fncmis.war/WEB-INF/classes/cmis.properties, and change cmisURI=http://hostserver to cmisURI=https://hostserver. And then restart the CMIS application.