
TIBCO ActiveMatrix BPM Installation and Configuration
204
|
Appendix B Securing Communication Channels
An SSL client and server negotiate a stateful connection by using a handshaking
procedure. During this handshake, the client and server agree on various
parameters to establish the connection's security. The handshake begins when a
client connects to an SSL-enabled server requesting a secure connection. The
server sends back its identification in the form of a digital certificate. The
certificate usually contains the server name, the trusted certificate authority (CA),
and the server's public encryption key.
You can specify the SSL configuration of the communication channels at various
times in the life cycle of a TIBCO ActiveMatrix BPM enterprise. Table 62 on
page 204 lists how to perform the initial SSL configuration and how to upgrade,
downgrade, and change the configuration of each channel. Detailed steps for each
procedure are provided in Chapter 5, Creating and Configuring Runtime Objects,
on page 92 and TIBCO ActiveMatrix Administration guide.
Table 62 SSL Configuration Summary
Key Channel Initial Configuration
Upgrade, Downgrade or
Change Configuration
1TIBCO ActiveMatrix
Administrator server
(external HTTP port) -
web and CLI clients
When creating ActiveMatrix
Administrator server in
TIBCO Configuration Tool.
Upgrade or downgrade:
ActiveMatrix Administrator CLI
Change SSL configuration:
ActiveMatrix Administrator CLI
2TIBCO ActiveMatrix
Administrator server
(internal HTTP port) -
hosts and nodes
When creating ActiveMatrix
Administrator server in
TIBCO Configuration Tool.
Upgrade or downgrade:
ActiveMatrix Administrator web
UI or CLI
Change SSL configuration:
ActiveMatrix Administrator web
UI or CLI
3TIBCO ActiveMatrix
Administrator server
- TIBCO Enterprise
Message Service
server
When creating ActiveMatrix
Administrator server in
TIBCO Configuration Tool.
Upgrade or downgrade:
ActiveMatrix Administrator web
UI or CLI
Change SSL configuration:
ActiveMatrix Administrator web
UI or CLI
4 TIBCO Host instance
- TIBCO Enterprise
Message Service
server
When creating ActiveMatrix
Administrator server or
TIBCO Host instance in
TIBCO Configuration Tool.
Upgrade or downgrade:
ActiveMatrix Administrator CLI
Change SSL configuration:
ActiveMatrix Administrator CLI
Commentaires sur ces manuels