|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Set up the TLS certificate
Step 1. Obtain an X.509 TLS certificate. Obtain the certificate from a trusted Certificate Authority.
Step 2. Install the certificate. On the machine that hosts the Business Tier, use the Windows Certificate Manager utility, certlm, to install the certificate in the Trusted Root Certification Authorities certificate store. If certlm is not available from the Start menu, open:
C:\WINDOWS\SYSTEM32\CERTLM.MSC
Step 3. Bind the certificate. Use the netsh command to bind the X.509 TLS certificate to the IP address and port number on which the Business Tier will accept incoming messages from the HTTP server. Use this syntax:
netsh http add SSLcert ipport=0.0.0.0:8000 certstorename=Root appid={FFFFFFFF-FFFF-FFFFFFFF-FFFFFFFFFFFF} certhash=FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
Specify the command values
ipport
The IP address and port number on which the Business Tier will listen. Specify an IP address, or leave the value as 0.0.0.0 to listen on all IP addresses that refer to this machine.
certstorename
Use Root if the certificate was added to the Trusted Root Certification Authorities store.
appid
Generate a random GUID to identify the CAREWare HTTP server and use it for this parameter.
certhash
This value is also known as the certificate thumbprint. In certlm, go to Trusted Root Certification Authorities > Certificates, and double-click the X.509 TLS certificate that you added. Select the Details tab, and scroll to the Thumbprint field to find the value.
Set up CAREWare to use HTTPS
Step 1. Locate the HTTP server configuration file. The res_admin_settings.txt file is located at the following path by default:
C:\Program Files\CAREWare HTTP Server\cwhttp\res_admin
Step 2. Update the URLs. If CAREWare currently uses unencrypted communication between the Business Tier and HTTP server, the URLs in the state_url and get_doc_url fields begin with http. Change both values so they begin with https instead of http.
Step 3. Update the Business Tier protocol. Use the CW Admin utility to change the Server Settings value tagged CWBusinessTierProtocol from http to https.
Step 4. Restart and test. Save the settings, and restart both the Business Tier and HTTP server. Log in to CAREWare to test that HTTPS communication is working.
How to confirm it worked
Log in to CAREWare after restarting the Business Tier and HTTP server. A successful login confirms that the HTTP server can communicate with the Business Tier using the updated HTTPS settings.
|
|
Related References
|
|
|
