SSL Reference Manual

Using Your Own Server Key and Certificate Files ................................................. 105
The Public/Private Key Pair .................................................................................... 106
The Certificate Signing Request .............................................................................. 106
Obtaining a Certificate from a Third Party CA ....................................................... 106
Acting As Your Own CA ........................................................................................ 106
Example: How to Generate SSL Certificates Using OpenSSL................................ 107
Requesting the SSL Client to Present a Client Certificate ....................................... 111
Configuring SSL for Production as SSL Client ..................................................................... 111
Presenting a Client Certificate to the SSL server .................................................... 111
Security Considerations ......................................................................................................... 112
Protecting Against the Man-in-the-Middle Attack .................................................. 112
Protecting the Private Key File ................................................................................ 112
If the Private Key is Compromised ......................................................................... 112
TLS Alerts ............................................................................................................................. 113
Remote SSL Proxy 115
The RemoteProxy Component ............................................................................................... 115
RemoteProxy Installation ...................................................................................................... 115
To install RemoteProxy on a Client Workstation .................................................... 115
RemoteProxy Configuration .................................................................................................. 116
General Configuration Considerations .................................................................... 116
The Main Configuration Screen .............................................................................. 116
The Session Properties Window .............................................................................. 117
Session Parameter List ............................................................................................ 118
Copying a Configuration to Other Workstations ..................................................... 119
Appendix 121
Log Messages and Warnings ................................................................................................. 121
Startup messages ..................................................................................................... 121
Warning messages ................................................................................................... 123
Informational messages ........................................................................................... 127
Fatal Errors .............................................................................................................. 128
Troubleshooting of Typical Errors ......................................................................................... 130
Address already in use ............................................................................................. 130
Could not open xxx file ........................................................................................... 130
Decode Error ........................................................................................................... 130
Handshake Error ...................................................................................................... 130
Invalid address ......................................................................................................... 131
Security violation (error 4013) ................................................................................ 131
vi Contents HP NonStop SSL Reference Manual