80 likes | 216 Views
`. IIPS Conference 2005 SSL for Colleague UI. Overview of UI telnet Connections. Datatel’s Colleague UI Desktop Unsecure telnet – Port 23 Secure Sockets Layer telnet – Port 992. SSL Certificates. Certificates Identifies the server Server has the private key to match public key
E N D
` IIPS Conference 2005 SSL for Colleague UI
Overview of UI telnet Connections • Datatel’s Colleague UI Desktop • Unsecure telnet – Port 23 • Secure Sockets Layer telnet – Port 992 North Carolina Community College System H. Martin Lancaster, President www.nccommunitycolleges.edu Fifty-eight Institutions Educating and Training a World-Class Workforce
SSL Certificates • Certificates • Identifies the server • Server has the private key to match public key • Provides a cipher for packet encryption • User requests a connection • Server responds with a public key • Once there is agreement the server uses the certificate’s cipher to encrypt the data packets North Carolina Community College System H. Martin Lancaster, President www.nccommunitycolleges.edu Fifty-eight Institutions Educating and Training a World-Class Workforce
SSL Certificates • Where are SSL Certificates stored for Unidata? • Unidata provides the ssltelnet daemon • These locations: • /opt/SSL/certs • /datatel/release/LIVE17/INSTALL/.bsrcfile • /datatel/release/LIVE17/INSTALL/_SECUTX_ • What about securing the certificates? • Yes. Especially the private keys • Where are they and how do I protect them? North Carolina Community College System H. Martin Lancaster, President www.nccommunitycolleges.edu Fifty-eight Institutions Educating and Training a World-Class Workforce
Obtaining a Signed Certificate • Create a Certificate Request • Follow setup procedures in document • Submit a Certificate Request • Use NCCCS Certificate Authority • Install Signed Certificate • Your signed certificate is returned with the NCCCS Intermediate Certificate • Install signed certificate into Unidata North Carolina Community College System H. Martin Lancaster, President www.nccommunitycolleges.edu Fifty-eight Institutions Educating and Training a World-Class Workforce
Submitting a Certificate Request • NCCCS Website • Faculty and Staff • Administrative Resources • Systems • NCCCS Root Certificates North Carolina Community College System H. Martin Lancaster, President www.nccommunitycolleges.edu Fifty-eight Institutions Educating and Training a World-Class Workforce
Installing NCCCS Root Certificate • Refer to NCCCS Systems Sub-Web • Notify users • Continue testing • Steps to Increasing Security • Disallow unsecure connections • Remove telnet 23 (remember to activate for Datatel Installshield use) North Carolina Community College System H. Martin Lancaster, President www.nccommunitycolleges.edu Fifty-eight Institutions Educating and Training a World-Class Workforce
SSL for Colleague UI Questions ? • http://nccommunitycolleges.edu North Carolina Community College System H. Martin Lancaster, President www.nccommunitycolleges.edu Fifty-eight Institutions Educating and Training a World-Class Workforce