Defining security profiles

This section describes how to create, modify, and delete a security profile. All of the configuration tasks require you to first access the Security Profiles folder. To do this, highlight the Security Profiles folder from EAServer Manager.

See Table 13-3 when creating, modifying, or deleting a security profile.

StepsCreating a new security profile

  1. Highlight the Security Profiles folder and choose File | New Security Profile. The Security Profile wizard displays.

  2. Follow the wizard pages to configure the profile properties. For more information on these settings, click Help in the Wizard or see Table 13-3.

The new security profile now appears on the right side of the window when the Security Profiles folder on the left side of the window is highlighted.

StepsModifying an existing security profile

  1. Highlight the security profile you wish to modify.

  2. Choose File | Properties to display the Security Profile Properties dialog box with fields described in Table 13-3.

    Alternatively, choose File | Configuration Wizard to run the configuration wizard. For more information on the wizard settings, click Help in the Wizard or see Table 13-3.

StepsDeleting a security profile

  1. Highlight the profile entry you want to delete.

  2. Select File | Delete Security Profile.

Table 13-3: General, advanced, and Entrust profile properties

Property

Description

Comments/example

Name

The name you give to the security profile.

Description

A description of the security profile.

Use Entrust

Select this check box to use an Entrust ID instead of a certificate contained in the Sybase PKCS #11 token.

Selecting this check box prevents access to the certificates contained in the Sybase token.

Security Characteristic

Select a name from the drop-down list of predefined security characteristics to use for this profile.

See Table 13-2 for a description of security characteristics and the CipherSuites they support.

Description

A description of the selected security characteristic.

Each security characteristic comes with a description of its features.

Sybase PKCS #11 Token Certificate Label

From the drop-down list, enter the certificate label you want to use for this security profile.

If you have not provided the PIN for the Sybase PKCS #11 token, you are prompted for one. This is the same PIN that you enter to access the EAServer Manager | Certificates folder.

If you are using an Entrust ID and click the Use Entrust check box, this property does not appear.

See Chapter 14, “Managing Keys and Certificates” for more information on certificates.

SSL Cache Size

The number of entries in SSL session cache maintained by the server. The default cache size is 30.

See “SSL session caching and reuse”.

SSL Session Share

The number of concurrent connections that can simultaneously use the same session entry (ID) in the session cache. The default session share size is 10.

See “SSL session caching and reuse”.

SSL Session Linger

The duration for which a session entry is kept in the SSL session cache after the last SSL session using this session ID was closed. The default session linger value is eight hours.

See “SSL session caching and reuse”.

Log SSL Errors

When selected, additional information about SSL errors is logged.

Set Defaults

Select the Set Defaults check box to restore all of the advanced settings to their default levels.

Specify the Entrust INI File

Enter the complete path to the Entrust initialization file.

You can use the browse feature to locate this file. For example, on Windows, %SystemRoot%\entrust.ini.

Entrust User Profile

Enter the complete path to the Entrust user profile file.

You can also use the browse feature to locate this file. There is no default.

Entrust Password

The password to the Entrust login for this Entrust user profile.

Allow non-Entrust client

Click this check box to allow non-Entrust clients to connect to listeners that use an Entrust ID.