Enabling SSL on the Server

Protocols are mostly configured on the Site; however, before configuring SSL on the Site, you must configure SSL and FIPS-approved connections on the Server.

Specify SSL versions and ciphers before enabling SSL connections. After you have enabled SSL for the Server, SSL connections can be enabled on the Site, Setting Template, and/or for each user. Each level can inherit the settings from the parent.

To configure SSL

  1. In the administration interface, connect to EFT Server and click the Server tab.

  2. In the left pane, click the Server node that you want to configure.

  3. In the right pane, click the Security tab.

  4. In the SSL Compatibility area, specify the SSL version to use:

    illust_sslcompatibility.gif

  5. In the Select from list box, select the check box of one or more Allowed ciphers to use or manually specify the ciphers. At least one cipher must be specified.

    icon_info.gif

    Only advanced users should manually specify ciphers.

  6. Click the Priority arrows to arrange the ciphers in top-down priority. If more than one approved cipher is specified, and the connecting client has in its list one or more ciphers that are also on EFT Server’s approved list, EFT Server will select and use the cipher based on ordering (priority) shown in the list box.

  7. In the FTPS Protocol Specific area, check the Allow Clear Command Channel (CCC) for FTPS connections and/or Allow unprotected data channel (PROT C) for FTPS connections, as needed. Users that attempt CCC or Prot-C must receive the appropriate FTP error code if not permitted by EFT Server. The client must then retry using protected command or data channels to connect.

  8. Click Apply to save the changes to EFT Server.

icon_info.gif

  • SSL Cipher and Version-allowed settings affect ALL Sites on EFT Server.

  • PCI DSS requirements mandate use of 128-bit or higher ciphers, and SSLv3, TLS or greater.

  • A Certificate Authority (CA)-signed certificate establishes your validity better than a self-signed certificate.

  • For details of SSL when using FIPS mode, refer to  FIPS-Compliant Protocols and Ciphers.