Secure Sockets Layer

Replication Agent supports use of the secure sockets layer (SSL) for connections to and from Replication Agent instances.

As a client, a Replication Agent instance can use SSL in connecting to servers, including:

Client applications can use SSL to encrypt connections to Replication Agent.

Replication Agent General Configuration for SSL

Each Replication Agent instance stores an asymmetric encryption key pair in an identity file located at the path indicated by ssl_identity_filename. The identity file is encrypted and is accessed with the password stored in ssl_identity_password. The Certificate Authority (CA) certificates for a Replication Agent instance are stored in a file located at the path indicated by ssl_certificates_filename.

Replication Agent as a Client

To connect to an Oracle data server, set the pds_use_ssl Replication Agent configuration parameter to true. To verify the distinguished name (DN) of the server certificate, set pds_ssl_sc_dn. Also specify the Oracle SSL port number using pds_port_number.

To connect to a Replication Server, set rs_use_ssl to true. To verify the DN of the Replication Server server certificate, set rs_ssl_sc_dn.

Replication Agent as a Server

To configure a Replication Agent instance to listen for SSL client connections on its administration port, set use_ssl to true. Clients must then use SSL to connect to the Replication Agent instance.

See the Replication Agent for Oracle Administration Guide and the Replication Agent for Oracle Reference Manual.