User guide
Chapter 2: Environment Setup (SSO Administrators)
2-56
− Protocol Version
Select 'SSL 3.0' only.
− Client Certificate
Select 'Yes (Authenticate when client certificate is presented)'.
− Encryption Method
Change the encryption method when necessary.
− Nickname of Certificate Authority
Change the nickname when necessary.
For details of the above items, refer to the Operator’s Guide.
2. Confirming the Validity of the Certificate
In addition to the above setup, the validity of the certificate authentication must be confirmed. This
process includes acquiring and registering the CRL in the Interstage certificate environment. When
the site certificates for the repository server (update system) and repository server (reference
system)are issued by different authorities, acquire the CRL from the certificate authority that issued
the certificate of the repository server(update system). Then register this CRL in the machine of the
repository server (reference system).For details, refer to Preparations for Confirming Validity of
Certificate Authentication.
Remarks
• Replication using SSL communication can protect confidential information since risks such as
electrical interception, alteration, and spoofing are avoided by SSL client-server authentication, and
communication between respective SSO repositories is encrypted. SSL communication is,
therefore, highly recommended for security.
• To set up the SSL communication environment on the repository server (reference system), do not
use a site certificate for test.
Creating an SSO Slave Repository of the Repository Server (Reference System)
Create the SSO repository for slave operation of replication on the machine on which the repository
server (reference system) is set up. On the Interstage Management Console of the machine on which
this repository server (reference system) is to be set up, perform the following procedure:
1. Select [Services] and then [Repository] from the System menu. Click the [Create a New
Repository] tab.
2. Specify the items as described below, and click the Create button.
Descriptions in bold indicate settings that must be the same as those of the SSO repository
(master). Items marked with (*1) can be specified only when the SSO repository is to be created.
These items cannot be changed after the SSO repository is created. Carefully set these items. For
other items, check values and change them when necessary.