13.1.9. Procedure – Configuring SSL handshake parameters

With the SSL handshake settings (SSL) parameter the certificate verification parameter and other handshake-related information can be set.

  1. Select verification level in the Verify depths field to decide how many levels are verified in the certificate hierarchy.

    Values from 0 to 100 are allowed.

  2. Choose Groups or Advanced with the radio buttons.

    Note

    It is recommended to use the PKI groups configuration.

    1. In Groups settings select the certificate entity for the ZMS host.

      For example: ZMS_engine: If the Certificate selector window is opened, it displays the unique identifier of the ZMS host and also certificate information, such as version, serial number, issue date and validity period, algorithms and keys. This information is useful when selecting which certificate to use.

    2. Select agents validator CA group.

      For example: ZMS_Host_CA: If the CA group selector window is opened, the CA group can be defined which is used to verify the certificate of the agents during the handshake. Data is available on CA group name, certificate name and certificate information for the selected CA groups.

      SSL settings

      Figure 13.16. SSL settings

      OR

    3. In Advanced settings enter manually the following data.

      • full path of the file where the private key is stored

      • certificate

      • CA directory identifying the directory where the CA certificate entities are stored

      • and CRL directory giving the place of the CRLs corresponding to the CA

        screenshot

      Advanced settings for SSL connection

      Figure 13.17. Advanced settings for SSL connection