You are using an unsupported browser. Please update your browser to the latest version on or before July 31, 2020.
You are viewing the article in preview mode. It is not live at the moment.
IMPORTANT: Upcoming Changes in CAREWare > Learn More
Home > Installing, Upgrading, and Migrating CAREWare 6 > HTTP Server Setup > Using HTTPS for communication between the HTTP server and Business Tier
Using HTTPS for communication between the HTTP server and Business Tier
print icon

 

 

Purpose

Configure encrypted HTTPS communication between the CAREWare 6 HTTP server and the Business Tier.

Who should do this

CAREWare system administrators and IT staff who manage the HTTP server and Business Tier.

Use this guide when you need to

Secure message exchanges between the HTTP server and Business Tier with a trusted X.509 TLS certificate.

Main warning

These steps do not configure HTTPS communication between a web browser and the CAREWare HTTP server.

 

Quick path
Install the TLS certificate on the Business Tier host > bind it with netsh > update res_admin_settings.txt > change CWBusinessTierProtocol to https > restart both services > test CAREWare.

 

Important: This procedure secures communication only between the HTTP server and Business Tier. It does not secure communication between the browser and HTTP server.

Set up the TLS certificate

Step 1. Obtain an X.509 TLS certificate. Obtain the certificate from a trusted Certificate Authority.

Step 2. Install the certificate. On the machine that hosts the Business Tier, use the Windows Certificate Manager utility, certlm, to install the certificate in the Trusted Root Certification Authorities certificate store. If certlm is not available from the Start menu, open:

C:\WINDOWS\SYSTEM32\CERTLM.MSC

Step 3. Bind the certificate. Use the netsh command to bind the X.509 TLS certificate to the IP address and port number on which the Business Tier will accept incoming messages from the HTTP server. Use this syntax:

netsh http add SSLcert ipport=0.0.0.0:8000 certstorename=Root appid={FFFFFFFF-FFFF-FFFFFFFF-FFFFFFFFFFFF} certhash=FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF

Specify the command values

ipport

The IP address and port number on which the Business Tier will listen. Specify an IP address, or leave the value as 0.0.0.0 to listen on all IP addresses that refer to this machine.

certstorename

Use Root if the certificate was added to the Trusted Root Certification Authorities store.

appid

Generate a random GUID to identify the CAREWare HTTP server and use it for this parameter.

certhash

This value is also known as the certificate thumbprint. In certlm, go to Trusted Root Certification Authorities > Certificates, and double-click the X.509 TLS certificate that you added. Select the Details tab, and scroll to the Thumbprint field to find the value.

Set up CAREWare to use HTTPS

Step 1. Locate the HTTP server configuration file. The res_admin_settings.txt file is located at the following path by default:

C:\Program Files\CAREWare HTTP Server\cwhttp\res_admin

Step 2. Update the URLs. If CAREWare currently uses unencrypted communication between the Business Tier and HTTP server, the URLs in the state_url and get_doc_url fields begin with http. Change both values so they begin with https instead of http.

Step 3. Update the Business Tier protocol. Use the CW Admin utility to change the Server Settings value tagged CWBusinessTierProtocol from http to https.

Step 4. Restart and test. Save the settings, and restart both the Business Tier and HTTP server. Log in to CAREWare to test that HTTPS communication is working.

How to confirm it worked

Log in to CAREWare after restarting the Business Tier and HTTP server. A successful login confirms that the HTTP server can communicate with the Business Tier using the updated HTTPS settings.

 

Important: These steps do not configure CAREWare to use HTTPS for communication between the browser and HTTP server.

Related References

Document

Use it for

CW Admin Utility

Use it to change the CWBusinessTierProtocol Server Settings value from http to https.

 

 

Feedback
0 out of 0 found this helpful

Attachments

CAREWare_User_Guide__Using_HTTPS_for_Communication_Between_the_HTTP_Server_and_Business_Tier.pdf
scroll to top icon