-
ESCWA
-
To ensure the
ESCWA network endpoint will honor the server cipher list, use
ESCWA to perform the following steps:
- Click
This opens the
Enterprise Server Administration Configuration dialog box.
- Expand
Server Settings
- Click
TLS Settings.
- Expand
Advanced.
- Check
Honor Server Cipher List
- Click
Apply.
- Restart the
ESCWA process.
- Directory Server
-
To ensure a Directory Server network endpoint will honor the server cipher list, use
ESCWA to perform the following steps:
- In the top menu bar, click
Native.
- In the
Native Navigation pane, expand
Directory Server.
- Click the directory server you require, then click
.
This takes you to the
Connections Properties page.
- Check
Enable TLS.
- Check
Use Custom Certificates.
- Expand
Advanced.
- Check
Honor Server Cipher List.
- Click
Apply.
- Restart the Directory Server process.
- Communications Process
-
To ensure a
region's Communications Process' network endpoint will honor the server cipher list, use
ESCWA to perform the following steps:
- In the top menu bar, click
Native.
- In the
Native Navigation pane, expand
Directory Server.
- Click the
region you require.
- Click
.
This opens the
Communications Server Properties page.
- In the
Native Listener Navigation pane, click the
Communications Process you require.
- Expand
Configure.
- Click
TLS Settings.
- Check
Enable TLS.
- In the
Certificate File field, type the location of the TLS certificate on the machine where this region runs.
- In the
Keyfile field, type the location of the TLS key on the machine where this region runs.
- In the
Server CA Root Certificate File field, type the location of the server CA root certificate on the machine where this region runs.
- Expand
Advanced.
- Check
Honor Server Cipher List.
- Click
Apply.
- Restart the
region so the changes are applied.
See
To Configure the Passphrase in a File for more information on setting the keyfile passphrase.
Next time the
region is started, the network endpoint will be TLS enabled.
- Listener
-
To ensure a
region's listener's network endpoint will honor the server cipher list, use
ESCWA to perform the following steps:
- In the top menu bar, click
Native.
- In the
Native Navigation pane, expand
Directory Server.
- Click the
region you require.
- Click
.
This opens the
Communications Server Properties page.
- In the
Native Listener Navigation pane, click the listener you require.
- Click
TLS Settings.
- Check
Enable TLS.
- In the
Certificate File field, type the location of the TLS certificate on the machine where this region runs.
- In the
Keyfile field, type the location of the TLS key on the machine where this region runs.
- Expand
Advanced.
- Check
Honor Server Cipher List.
- Click
Apply.
- Restart the
region so the changes are applied.
Next time the
region is started, the network endpoint will be TLS enabled.