Setting up full SSL security
About this task
To set full SSL connection security for your network, you must, in addition to
all the steps described above in Connection security overview) configure the
following options:
- enSSLFullConnection (or
sf) - Use
optmanon the master domain manager to set this global option toYesto enable full SSL support for the network. For more information, see Setting global options. - nm SSL full port
- If you defined the SSL port at installation time using
the netmansslport parameter, no further action is
required. For more information about the
netmansslport parameter, see Agent installation parameters - twsinst script,
Server components installation - serverinst script.If you have not defined the SSL port at installation time, edit the
localoptsfile on every agent of the network (including the master domain manager) to set this local option to the port number used to listen for incoming SSL connections. For more information, see Setting local options. Take note of the following:- This port number is to be defined also for the
SECUREADDRparameter in the workstation definition of the agent. For more information, see Workstation definition. - Check that the
securitylevelparameter in the workstation definition of each workstation using SSL is set at least to enabled. For more information, see Workstation definition. - In a full SSL security setup, the
nm SSL portlocal option is to be set to zero. For more information, see Setting local options. - You must stop netman
(conman shut;wait) and restart it
(StartUp) after making the changes in
localopts.
- This port number is to be defined also for the