Novell ACCESS MANAGER 3.1 SP2 - ACCESS GATEWAY GUIDE 2010 Manual page 87

Access gateway guide
Hide thumbs Also See for ACCESS MANAGER 3.1 SP2 - ACCESS GATEWAY GUIDE 2010:
Table of Contents

Advertisement

Certificates: If you have configured SSL or mutual SSL between the proxy service
and the Web servers, configure the Web Server Trusted Root and SSL Mutual
Certificate options. The export and import configuration option does not export and
import certificates.
1e Click OK twice.
2 (Conditional) If you have multiple reverse proxies, repeat
3 On the Configuration page, click Reverse Proxy / Authentication, then select the Identity Server
Cluster configuration.
4 If you have multiple reverse proxies, verify that the Reverse Proxy value in the Embedded
Service Provider section is the reverse proxy you want to use for authentication, then click OK
twice.
5 (Conditional) If the Administration Console already contained some policies, verify that you do
not have policies with duplicate names. Click Policies > Policies.
Policies with duplicate names have Copy-n appended to the end of the name, with n
representing a number. If you have duplicates, reconcile them:
If they contain the same rules, you need to reconfigure the resources that use one policy to
use the other policy before you can delete the duplicate policy.
If they contain different rules, rename the duplicate policies.
6 (Conditional) Apply any policy configuration changes.
7 Click Access Gateways > Update.
8 Click Identity Servers > Update.
If your Identity Server does not prompt you for an update, complete the following steps to
trigger the update:
8a In the Administration Console, click Devices > Access Gateways > Edit > Reverse Proxy /
Authentication.
8b Set the Identity Server Cluster field to None, then click OK.
8c Click Reverse Proxy / Authentication.
8d Set the Identity Server Cluster field to the correct value, then click OK.
8e Update the Access Gateway.
8f Update the Identity Server.
9 Configure the keystores for the Access Gateway.
If you have configured the Access Gateway for SSL between the Identity Server and the
Access Gateway and between the Access Gateway and the browsers, verify that the trust stores
and the keystores contain the correct certificates.
9a In the Administration Console, click Security > Certificates.
9b Find the certificate for the Access Gateway.
The subject name of this certificate should match the DNS name of the Access Gateway. If
this certificate is not in the list, you need to create it or import it.
This certificate should be in use by the ESP Mutual SSL and Proxy Key Store of the
Access Gateway.
Step 1
for each proxy service.
Server Configuration Settings
87

Advertisement

Table of Contents
loading

Table of Contents