Hi Alexsandrs,
please make sure that you have the latest fixes applied (at least IS-Core-Fix27 and related SCG-Entrust-Fix/SCG_Security_Fix.)
This is neccessary for the migration anyway and it gives you the possibility to disable SSL Protocols for both directions.
For the certificates:
1)
Get OPENSSL donwloaded (for windows in your case) and installed.
Create a private key and a csr for your host.
Your partner should do the same for theirs.
Question: Who will sign these csr´s? Is one of you having a company specific CA-Issuing department?
-
Check under IS-Admin->Security->Ceritificates.
There you can specify the private key, the server´s signed certificate, the CA (by which the certificate was signed) as well as a directory, where additional certificates (like your partners server certificate and related CA).
All these certificates should be formatted as DER-certificate format. OPENSSL or Windows itself can be used for converting.
Refresh the "Trusted CA Certificates Cache".
Additionally you might have to restart your IS.
Then you configure an HTTPS-Port, on which you will listen to the WS-Calls from your partner.
There is no need to set any WSS Handlers, when only transport security with Basis Authentication is used.
Just one more question about the workflow:
Is this just logic in the IS/ProcessEngine or is this a real workflow using TaskEngine (which resides in MWS)?
Regards,
Holger
#webmethods-Protocol-and-Transport#Integration-Server-and-ESB#webMethods